Impact
A local privilege exploitation flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 allows an attacker who has logged on locally with high-privileged credentials to elevate their privileges within the application and bypass the intended data access controls. The vulnerability enables the attacker to read a subset of the data and perform unauthorized update, insert, or delete operations, thereby compromising confidentiality and integrity of the system data. The weakness corresponds to improper access control.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is the only officially documented affected build, deployed by Oracle Corporation. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 Base Score of 3.0 indicates a low overall severity, and the vector (AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N) shows that exploitation requires local access with high-privileged credentials. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Consequently, risk is confined to compromised local users with administrative or equivalent privileges, and no remote exploitation path exists.
OpenCVE Enrichment