Impact
The vulnerability resides in the installation and configuration component of Oracle Hyperion Infrastructure Technology and permits an unauthenticated attacker who can reach the target’s physical communication segment to compromise the system. Successful exploitation results in full control of Hyperion, enabling an adversary to alter, delete or exfiltrate data and potentially disrupt critical business processes. The flaw carries a CVSS v3.1 base score of 7.5, indicating high severity with simultaneous loss of confidentiality, integrity, and availability.
Affected Systems
The only affected product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, delivered by Oracle Corporation. No other versions or products are listed as impacted in the CNA data.
Risk and Exploitability
The AV:A vector specifies that the attack requires physical or local network proximity to the hardware’s communication segment, while the high attack complexity, no privilege requirement, and no user interaction simplify the execution for a skilled adversary. The EPSS score of < 1% indicates a low but non‑zero likelihood of exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. Consequently, organizations with exposed Hyperion servers face a significant risk if the physical interface is not adequately secured or monitored.
OpenCVE Enrichment