Impact
A vulnerability exists in Oracle Hyperion Infrastructure Technology 11.2.25.0.000 that permits an unauthenticated attacker with network access over HTTPS to compromise the system. Successful exploitation can yield the creation, deletion, or modification of critical data and grant the attacker unrestricted or complete access to all data managed by the platform, leading to significant confidentiality and integrity violations.
Affected Systems
Oracle Hyperion Infrastructure Technology, a product of Oracle Corporation, specifically version 11.2.25.0.000 in its Common Security component.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 denotes medium‑high severity. EPSS information is unavailable, indicating that exploitation data is not currently tracked, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is external over HTTPS with no authentication prerequisites, implying that an adversary can initiate the compromise from any accessible network segment. Consequently, the risk remains substantial due to the potential for broad data compromise and the absence of a known public exploit.
OpenCVE Enrichment