Impact
The vulnerability is an easily exploitable flaw in the Common Events component of Oracle Hyperion Infrastructure Technology that allows a low-privileged attacker with network access over HTTP to compromise the system. The flaw is a Privilege Escalation issue identified as CWE-284, and successful exploitation can grant unauthorized access to critical data or full access to all data that the Hyperion Infrastructure services can present, resulting in a confidentiality compromise as indicated by the CVSS 3.1 vector.
Affected Systems
Affected systems include Oracle Hyperion Infrastructure Technology from Oracle Corporation, specifically version 11.2.25.0.000. The advisory notes that while the vulnerability resides in Oracle Hyperion Infrastructure Technology, the effect can extend to other products that rely on it, indicating a scope change.
Risk and Exploitability
The CVSS base score of 7.7, a low attack complexity, a network attack vector, and only low privilege requirements combine to produce a moderate to high risk. The EPSS score of <1% suggests a very low exploitation probability at present, and the issue is not listed in the CISA KEV catalog. However, an attacker with HTTP access to the affected endpoints can exploit the flaw remotely, potentially compromising data confidentiality and, through scope change, affecting other dependent components.
OpenCVE Enrichment