Impact
A vulnerability exists in the Common Events component of Oracle Hyperion Infrastructure Technology that allows an unauthenticated attacker with network access over HTTP to modify, delete, or insert data while also being able to read a portion of the system’s data. The flaw results in a loss of confidentiality and integrity for affected data, with no direct impact on availability reported at this time.
Affected Systems
The affected product is Oracle Hyperion Infrastructure Technology from Oracle Corporation, version 11.2.25.0.000, as identified via the Common Platform Enumeration string for that release.
Risk and Exploitability
The CVSS v3.1 score of 4.8 indicates moderate severity, with medium complexity and no authentication required. Although the EPSS score is not available, the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting it is not actively targeted in the wild yet. An attacker who can reach the application over HTTP could exploit the flaw to gain unauthorized read and write access to sensitive business data simply by sending crafted requests, potentially compromising data integrity and leaking confidential information.
OpenCVE Enrichment