Impact
The flaw resides in the Common Events component of Oracle Hyperion Infrastructure Technology. A low‑privileged attacker with network access can send crafted SQL statements that are executed with system privileges. Successful exploitation results in full takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, from Oracle Corporation, is the only product and version listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects high severity across all three core security dimensions. The attack vector is network‑based, requires low privileges and no user interaction. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, yet the potential for application takeover warrants urgent attention.
OpenCVE Enrichment