Impact
A flaw exists in the Common Security component of Oracle Hyperion Infrastructure Technology that allows a low‑privileged attacker with network access to the HTTP interface to gain unauthorized access to critical data or all data the application can serve. The vulnerability provides a confidentiality breach, enabling data exfiltration without authentication. No denial of service or integrity impact is described.
Affected Systems
Oracle Corporation's Hyperion Infrastructure Technology, specifically version 11.2.25.0.000. No other vendor or product versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity with a low complexity and low required privileges for exploitation. The EPSS score of 0.00371 (<1%) indicates a very low probability of exploitation but provides a quantifiable risk. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based via HTTP, implying that any host able to reach the service can attempt exploitation.
OpenCVE Enrichment