Impact
The vulnerability lies in the Common Events component of the Oracle Hyperion Infrastructure Technology product, and an unauthenticated attacker with network access to the HTTP interface can exploit this flaw to read a subset of data. The flaw provides data exposure at a low confidentiality level, as indicated by the CVSS vector and score.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 from Oracle Corporation is affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack surface is the public HTTP endpoint, and exploitation requires no credentials or special privileges—an unauthenticated attacker only needs network access to the vulnerable interface. The risk is primarily the potential leakage of limited information rather than full system compromise.
OpenCVE Enrichment