Impact
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 contains an implementation flaw in its installation and configuration component that fails to enforce proper authentication for HTTP requests. An unauthenticated attacker on the network can send specially crafted HTTP traffic to the affected system and perform data modifications (update, insert, delete) on any accessible data. The attacker also gains read access to some protected data and can trigger a partial denial of service that temporarily disrupts availability. Together, these capabilities compromise the confidentiality, integrity, and availability of the system as reflected in the CVSS scoring.
Affected Systems
The vulnerability is limited to Oracle Hyperion Infrastructure Technology, specifically the 11.2.25.0.000 release. Only users who run this version and expose the HTTP interface to a network are vulnerable, as the flaw resides in the installation and configuration manager. Affected developers and administrators should verify the installed version and confirm that no unpatched instances remain exposed.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high impact with ease of exploitation. The vulnerability requires network connectivity to the HTTP interface and does not require prior authentication, making it trivially exploitable. While no EPSS value is published, the lack of a KEV entry means no known active exploitation is reported, yet the exploit conditions are simple enough that a threat actor could abuse the flaw rapidly if the product remains publicly reachable. Prompt remediation is recommended given the clear path to unauthorized data alteration and service disruption.
OpenCVE Enrichment