Impact
The vulnerability resides in the Common Events component of Oracle Hyperion Infrastructure Technology and is a CWE‑284 access control weakness that permits an unauthenticated attacker to read confidential data and write, update, or delete records once user interaction can establish an authenticated session. The flaw can lead to compromise of sensitive information and integrity violations, affecting data stored by the system.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, Common Events component.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates a high‑severity flaw. The EPSS score of less than 1 % suggests a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Still, the flaw is exploitable over an HTTP interface and requires only network access, making it a potential vector for attackers who can persuade a user to trigger the exploit. The requirement for user interaction limits the attack to scenarios where a legitimate user becomes the target of a social‑engineering or phishing action, but the potential impact on confidentiality and integrity remains significant.
OpenCVE Enrichment