Impact
A flaw exists in the Common Security component of Oracle Hyperion Infrastructure Technology that allows a low‑privileged attacker with network access to the HTTP interface to gain unauthorized access to critical data or to all data the application can serve. The vulnerability provides a confidentiality breach, enabling data exfiltration without authentication. No denial of service or integrity impact is described. The affected version is 11.2.25.0.000.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology, specifically version 11.2.25.0.000. No other vendor or product versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity with a low complexity and low required privileges for exploitation. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based via HTTP, implying that any host able to reach the service can attempt exploitation.
OpenCVE Enrichment