Impact
The vulnerability resides in the installation and configuration processes of Oracle Hyperion Infrastructure Technology. An attacker who already has low‑privilege access to the infrastructure can exploit this weakness to create, delete, or modify critical data, resulting in significant compromise of data integrity and confidentiality. The described impact indicates that any data accessible through Oracle Hyperion can be altered or accessed without proper authorization. Based on the CVSS vector, the flaw requires local access with low privileges and no user interaction, and it has high impacts on confidentiality and integrity.
Affected Systems
The defect affects Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. No other versions or products are listed as impacted. This single supported version is the target of the vulnerability.
Risk and Exploitability
The CVSS base score of 7.1 reflects a high level of risk. Because the EPSS score is 0.00149 (< 1%), the probability of exploitation is very low but not zero, and the lack of a KEV designation suggests the vulnerability has not yet been widely exploited. The stated local attack vector combined with low privilege requirements means that systems with weak account controls or poorly segregated roles are at higher risk. Attackers can achieve the described unauthorized data manipulation by simply executing a legitimate configuration operation under a low‑privilege account.
OpenCVE Enrichment