Impact
A flaw in the Common Events component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker to send crafted HTTP requests and gain full administrative control over the service. The vulnerability results in loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Hyperion Infrastructure Technology – version 11.2.25.0.000 is the only affected release. No other versions are mentioned as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity. The EPSS score of less than 1% shows a very low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack is possible from any host that can reach the HTTP interface and does not require authentication, making it a remote takeover threat.
OpenCVE Enrichment