Impact
A weakness in the Common Security component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to attempt to compromise the system. The flaw requires a human user other than the attacker to interact with the malicious request, but once activated the system can expose all data normally protected, giving the attacker read access to critical data or total access to all data the application can handle. The vulnerability, rated CVSS 3.1 Base Score 6.5 with a vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, represents a confidentiality breach without direct impact on integrity or availability.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is the only affected release identified in public advisories. Systems running this exact version without the vendor’s fix are vulnerable to the flaw. The product is provided by Oracle Corporation.
Risk and Exploitability
The moderate CVSS score indicates the vulnerability can be reached remotely via HTTP, but it requires user interaction for exploitation. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting no known active exploitation. Attackers would need to persuade an internal user to interact with a malicious request, making phishing or social engineering tactics the primary attack vector. The risk is focused on confidentiality loss rather than integrity or availability disruptions.
OpenCVE Enrichment