Impact
A flaw in Oracle Hyperion Infrastructure Technology enables a low‑privileged attacker who can reach the system over HTTP to compromise the application and obtain unauthorized access to critical data. Successful exploitation grants the attacker the ability to read all data exposed by the application and to insert, update or delete records, thereby impacting confidentiality and, to a lesser extent, integrity. The vulnerability does not provide remote code execution but allows an attacker to elevate privileges within the application’s context and manipulate data normally safeguarded by business rules.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology, version 11.2.25.0.000, is vulnerable. The affected component is the Common Security module and the issue may also affect other related products within the Hyperion stack through scope change. No other products or versions are listed as affected in the available CNA data.
Risk and Exploitability
The CVSS score of 7.1 reflects a medium‑to‑high severity vulnerability with network‑based attack vector, high complexity, low privilege requirement, and no user interaction. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access to the HTTP interface of the affected product, which can be achieved from an external or internal attacker’s machine. Once achieved, the attacker can obtain sensitive business data and modify or delete it, potentially leading to financial loss, regulatory non‑compliance, and damage to business operations.
OpenCVE Enrichment