Impact
The vulnerability lies in the installation and configuration component of Oracle Hyperion Infrastructure Technology, permitting an unauthenticated attacker with network access to gain full control over the system. Successful exploitation can lead to unauthorized access to critical data or complete access to all data stored in the Hyperion platform. The weakness directly impacts confidentiality, with no immediate integrity or availability effects.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version explicitly affected. The vulnerability is within the installation and configuration component that is common to all Oracle Hyperion environments deploying this version. No other vendor or product versions are indicated as impacted from the current data. Additionally, the vulnerability’s scope change may affect other products beyond the Hyperion platform.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates high severity, and the vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) shows that an unauthenticated attacker can remotely exploit the flaw through multiple network protocols. EPSS is < 1%, indicating a very low but non‑zero probability of exploitation; however, the lack of a KEV listing does not diminish the seriousness of the issue. The vulnerability’s scope change may allow attackers to impact additional products beyond Hyperion, and publicly disclosed nature and the common vector suggest potential exposure in enterprise environments. Attackers could exploit this weakness by sending crafted configuration requests from any accessible network segment, bypassing authentication, and assuming system‑wide rights.
OpenCVE Enrichment