Impact
The Oracle Hyperion Infrastructure Technology installation and configuration component contains a flaw that enables unauthenticated attackers to exploit a network‑facing HTTP interface, gaining full control over the system. An attacker can compromise the confidentiality, integrity, and availability of the application, effectively taking it over. The vulnerability is described as "Easily exploitable", indicating a low effort and minimal technical barrier to impact.
Affected Systems
Affected vendor: Oracle Corporation; product: Oracle Hyperion Infrastructure Technology. The only explicitly vulnerable version is 11.2.25.0.000. No other releases are mentioned.
Risk and Exploitability
The CVSS base score of 9.8 marks the flaw as Critical, with maximum severity on confidentiality, integrity, and availability. The attack vector is network‑based, no authentication required, so any unauthenticated user with HTTP access can exploit it immediately. The EPSS score is < 1%, indicating a very low probability of exploitation, and the flaw is not listed in the KEV catalog. The high CVSS score and the nature of the vulnerability highlight an urgent need for remediation, as attackers can use simple automated tools to compromise the system.
OpenCVE Enrichment