Impact
An unauthenticated attacker with network access via HTTP can read a subset of data exposed by the Oracle Hyperion Infrastructure Technology installation. The flaw exists in the Installation and Configuration component and manifests as improper access control that allows unauthorized data read. This weakness affects confidentiality while integrity and availability remain unaffected.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is the only version identified as vulnerable in the Oracle security advisory. No other versions or related components are noted as affected, so the risk is confined to deployments running this specific build.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 indicates moderate potential for data exposure, and the EPSS score of less than 1 % suggests a low but not negligible likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited over the open network without authentication, environments that store sensitive data should treat this as a realistic threat and act promptly.
OpenCVE Enrichment