Impact
A vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw can lead to full takeover, resulting in loss of confidentiality, integrity, and availability as the attacker can execute arbitrary actions on the affected system. The weakness is a classic unauthorized access issue that effectively grants immediate code execution privilege.
Affected Systems
Oracle Hyperion Infrastructure Technology 11.2.25.0.000 is affected. No other versions are listed in the available data.
Risk and Exploitability
The CVSS v3.1 score of 9.8 indicates high impact with no required privileges. The attack vector is remote over HTTP, and the vulnerability is easily exploitable as no user interaction is required. Exploit likelihood appears low, with an EPSS score of < 1%, and the vulnerability is not listed in CISA’s KEV catalog. The potential for an attacker to seize control of the system makes this a critical security concern.
OpenCVE Enrichment