Impact
This vulnerability is located in the installation and configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. It allows a local, low‑privileged attacker—someone who can log on to the system where the product runs—to create, delete, or modify critical data. The exploit does not require elevated privileges or a user interface, and it can lead to significant confidentiality and integrity damage while leaving availability unaffected. The weakness stems from insufficient privilege checks that let non‑administrator users perform actions normally reserved for higher‑level accounts.
Affected Systems
Oracle Hyperion Infrastructure Technology 11.2.25.0.000, supplied by Oracle Corporation, is deployed in environments where users have local logon but are not administrators. The flaw is contained in the installation and configuration part of the product.
Risk and Exploitability
The CVSS 3.1 score of 7.1 reflects a high impact on confidentiality and integrity, with a local attack vector and low effort requirements. The EPSS score of < 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, meaning no known exploitation has been reported. An attacker with local access can change product data without elevated privileges, potentially causing serious business or regulatory consequences.
OpenCVE Enrichment