Impact
Oracle Hyperion Infrastructure Technology’s Lifecycle Management component contains a flaw that allows an attacker with low privileges and network connectivity over HTTP to create, delete, or modify critical data. The vulnerability is easily exploitable, permitting unauthorized changes to both confidentiality and integrity, and a scope change can affect related Oracle products. Attackers could gain complete access to all Hyperion data, jeopardizing business operations and exposing sensitive information.
Affected Systems
Version 11.2.25.0.000 of Oracle Hyperion Infrastructure Technology, including the Lifecycle Management component, is affected. The vulnerability applies only to this exact build, but a scope change may also expose additional Oracle products that interact with Hyperion data.
Risk and Exploitability
With a CVSS v3.1 base score of 9.6, the flaw is critical. An attacker needs only network connectivity over HTTP and low‑privilege credentials to exploit. Whether authentication is required prior to exploitation is not explicitly stated; based on the description, it is inferred that authentication may be required. The EPSS score is less than 1 %, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Given the potential for full data integrity compromise and exposure of linked products, the issue demands prompt remediation.
OpenCVE Enrichment