Impact
An unauthenticated attacker with network access via HTTP can read a subset of data exposed by the Oracle Hyperion Infrastructure Technology installation. The vulnerability resides in the Installation and Configuration component and does not require authentication, allowing the attacker to gain information that may be confidential. The impact is limited to confidentiality; integrity and availability are not affected. The weakness is an improper access control flaw that permits unauthorized data read access.
Affected Systems
The affected product is Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, as noted in the Oracle security advisory. Only this specific version of the Hyperion product is vulnerable; no other versions or components are mentioned.
Risk and Exploitability
The CVSS base score of 5.3 reflects moderate potential for data exposure. The exploit is network‑based and requires no prior authentication, making it easily exploitable over HTTP. EPSS is not available, so the current exploitation probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog, but because it allows unauthenticated read access, it should be considered a moderate to high operational risk for environments where Sensitive data is handled.
OpenCVE Enrichment