Impact
A vulnerability exists in the Common Security component of Oracle Hyperion Infrastructure Technology that can be exploited by an adversary who gains high privileged access over the network. Successful exploitation may allow the attacker to update, insert, or delete data that is normally protected, and can also cause a partial denial of service. The weakness is reflected in a CVSS score of 3.3, indicating that the threat primarily affects data integrity and availability but not confidentiality.
Affected Systems
Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version documented as affected.
Risk and Exploitability
The CVSS base score of 3.3 highlights that the exploit is not trivial but poses a legitimate risk to data integrity and system availability. The EPSS score is unavailable, and the vulnerability has not been listed in CISA's KEV catalog. The publicly available description indicates that the attack vector requires network access via HTTP, and the attacker must already possess high privileges. While the vulnerability is considered difficult to exploit, the potential impact warrants proactive mitigation.
OpenCVE Enrichment