Impact
The vulnerability resides in the Common Events component of Oracle Hyperion Infrastructure Technology. A low‑privileged attacker with network access limited to HTTP can exploit it to compromise the system, leading to full takeover of the application. The flaw likely stems from improper access control, resulting in confidentiality, integrity, and availability impacts as reflected in the CVSS 3.1 score of 8.8.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. This includes environments running the Hyperion Infrastructure Technology application, specifically the Common Events service exposed over HTTP.
Risk and Exploitability
A network attacker can reach the vulnerable HTTP interface, and the weakness allows execution of arbitrary actions with local privileges, so the attack vector is effectively remote. The CVSS base score of 8.8 indicates severe risk, and although EPSS data is not available, the high score and lack of mitigations in the default configuration suggest a significant likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog, but it remains a high‐risk exposure until remediation occurs.
OpenCVE Enrichment