Impact
A vulnerability in Oracle Hyperion Infrastructure Technology’s Common Events component allows an attacker with low privileges and network access via SQL to compromise the system. Successful exploitation can lead to full takeover of the application, compromising confidentiality, integrity, and availability across the infrastructure.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other versions or vendors are listed.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates high severity, with impacts on all three core security dimensions. The attack vector is network-based, requiring only low privileged access and no user interaction. While the EPSS score is not available, the lack of a KEV listing implies no known exploitation yet. Nonetheless, the potential for a full compromise warrants immediate attention.
OpenCVE Enrichment