Impact
A flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 permits a network attacker who does not authenticate to interact with the system over HTTPS, enabling unauthorized creation, deletion, or modification of critical data, as well as full access to all data stored by the platform. The weakness involves improper authentication and access control and has been documented as CWE-284, compromising both confidentiality and integrity of the data.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is the only product and version identified as affected in the advisory. No other versions or components are mentioned.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 7.4, indicating significant confidentiality and integrity impact. The EPSS score is less than 1 %, meaning the probability of exploitation in the wild is low. It is not listed in CISA’s KEV catalog. The flaw can be exploited remotely over HTTPS without any authentication, making it a straightforward target for adversaries who can reach the Hyperion service. Successful exploitation leads to unauthorized data manipulation or theft.
OpenCVE Enrichment