Impact
A vulnerability exists in Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 that allows an attacker who can reach the system over HTTPS to create, delete, or modify critical data without authentication. Successful exploitation grants the attacker full or near‑total access to all data managed by the platform, resulting in significant confidentiality and integrity violations.
Affected Systems
Oracle Corporation’s Oracle Hyperion Infrastructure Technology, component Common Security, version 11.2.25.0.000.
Risk and Exploitability
The CVSS 3.1 score of 7.4 indicates medium‑high severity. EPSS is reported as < 1%, implying that, at present, exploitation of this weakness is considered unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is external over HTTPS with no authentication required, meaning that any network host that can reach the service could attempt to exploit it. Consequently, the risk remains high due to the broad data impact and the lack of publicly known exploits.
OpenCVE Enrichment