Impact
The Oracle Hyperion Infrastructure Technology product contains a flaw in its Common Security component that lets a low‑privileged attacker establish an HTTP session and create, delete, or alter critical data. The vulnerability is exploitable over a network connection only, without user interaction, and the malicious actor can gain unrestricted write access to all data the Hyperion system exposes to users. This results in both confidentiality and integrity compromise for the affected data.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. Users of this specific release should verify that their instances are not exposed to untrusted networks and that only authorized organization roles are granted write privileges.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity with major confidentiality and integrity impacts. The EPSS score of less than 1% suggests that public exploitation is currently low, but the vulnerability is not listed in the CISA KEV catalog. Regardless, the attack vector (remote network access via HTTP) combined with low attack complexity and low privileges means that an attacker can compromise the system with minimal effort if the Hyperion instance is reachable.
OpenCVE Enrichment