Impact
The vulnerability resides in the Common Events component of Oracle Hyperion Infrastructure Technology and is a CWE-284: Improper Access Control weakness. Based on the description, a low‑privileged attacker with network access via HTTP can compromise the application, potentially leading to takeover and affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The flaw impacts the Common Events service that is exposed over HTTP. Environments running this version and accessible from the network are at risk.
Risk and Exploitability
Based on the description, low‑privileged attackers with network access via HTTP can exploit the vulnerability. The CVSS base score of 8.8 signals severe risk. The EPSS score of less than 1 % indicates a low probability of widespread exploitation, but the high impact means the vulnerability remains a serious threat. It is not presently added to the CISA KEV catalogue.
OpenCVE Enrichment