Impact
The vulnerability lies in the Oracle Hyperion Infrastructure Technology installation and configuration component. An unauthenticated attacker who can reach the service over HTTP can trigger an exploit that grants full control of the system. The weakness results in a compromise of confidentiality, integrity, and availability because the attacker can modify or delete data, create new users, or run arbitrary commands.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The flaw is present in the installation and configuration component that listens for HTTP requests, and no other versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates a critical severity with complete impacts on all CIA triad aspects. The EPSS score is below 1 %, suggesting that exploitation is currently unlikely, and the vulnerability is not cited in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the attack requires only unauthenticated network access over HTTP, high attack efficiency, and no authentication, making it a high‑risk target for externally exposed installations.
OpenCVE Enrichment