Impact
The vulnerability resides in the installation and configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 and allows an unauthenticated attacker with network access over HTTP to gain unauthorized access to all data exposed by the product. While the description indicates that the attacker could potentially gain full control, this is inferred rather than directly stated, and the risk is that the attacker could achieve complete compromise of the Hyperion environment. This weakness corresponds to an access control vulnerability.
Affected Systems
Affected vendors include Oracle Corporation. The vulnerable product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. No other versions are explicitly listed as affected in this advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 underscores a high severity threat with a network-access (AV:N) vector and low attack complexity (AC:L). The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely abused. Nevertheless, because no authentication is required and an HTTP interface is exposed, it is inferred that an internal or external attacker with network connectivity could potentially exploit this flaw.
OpenCVE Enrichment