Impact
Oracle Hyperion Infrastructure Technology is vulnerable to remote code execution flaw that exploits unauthenticated HTTP access in its installation and configuration component. The weakness allows an attacker to take full control of the system, compromising confidentiality, integrity, and availability. The issue was assigned a CVSS v3.1 base score of 9.8, indicating a critical level of risk and the potential for a total system takeover.
Affected Systems
Vulnerability affects Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.
Risk and Exploitability
The flaw is exploitable via an unauthenticated HTTP interface, but the CVE does not explicitly state whether the interface is publicly exposed. Based on the description, it is inferred that the service may be reachable from the internet, making it a likely public HTTP attack vector. The EPSS score of <1% indicates a very low probability of exploitation, yet the CVSS score of 9.8 underscores its high severity. The vulnerability is not listed in the CISA KEV catalog, but its critical nature and direct access vector suggest an adversary could mount an attack quickly and successfully if the system is exposed to the internet.
OpenCVE Enrichment