Impact
The vulnerability resides in the Lifecycle Management component of Oracle Hyperion Infrastructure Technology. An unauthenticated attacker with network access via HTTP can exploit the flaw, resulting in a full compromise of the affected system. Successful exploitation compromises confidentiality, integrity, and availability, effectively allowing the attacker to take over the application.
Affected Systems
The affected vendor is Oracle Corporation, product Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity. Exploitation requires only network access over HTTP and does not require authentication, making this a remote threat. The EPSS score of <1% suggests that, at present, the likelihood of exploitation is low, yet the potential impact remains severe. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high confidentiality, integrity and availability impact and the unauthenticated nature makes it a serious risk for any exposed Hyperion installation.
OpenCVE Enrichment