Impact
This vulnerability in the Common Security component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker that can reach the system over HTTP to influence privileged operations. Based on the CVE description, attackers can modify data when another user interacts with the web interface; this suggests that the flaw may stem from inadequate authorization enforcement. The impact includes both integrity and confidentiality violations, and the effect can extend beyond the reported product (a scope change) to other applications that share data or services with Hyperion.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 from Oracle Corporation is the only version identified as vulnerable; no other Hyperion releases or related components are listed.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, with the vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L) showing that network access, low effort, no privileges, and required user interaction are involved. The EPSS score of less than 1% signals that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw permits unauthenticated drivers to manipulate data via an HTTP-facing service, a determined adversary could leverage social engineering to obtain the necessary user interaction. If triggered, the attacker could alter critical business data or read confidential reports, potentially affecting additional products that rely on the same data layers. The risk is amplified when the web interface is exposed to the public or untrusted networks.
OpenCVE Enrichment