Impact
The Oracle Hyperion Infrastructure Technology product contains a defect in its Common Security component that permits an attacker with low privileges to connect over HTTP and create, delete, or alter critical data. The vulnerability enables the attacker to gain full write access to any data accessible through the Hyperion infrastructure, delivering both confidentiality and integrity breaches without impacting availability.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. Users of this release should ensure that their instances are neither exposed to the internet nor accessible to untrusted networks.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity with significant confidentiality and integrity impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. However, the vector AV:N/AC:L/PR:L/UI:N indicates that a remote attacker can exploit this with minimal effort and only network access, making the risk substantial for exposed deployments.
OpenCVE Enrichment