Impact
Oracle Hyperion Infrastructure Technology contains an installation and configuration flaw that allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to all data exposed by the product. The vulnerability is exploitable remotely and results in a confidentiality breach, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H. No impact on integrity or availability is described.
Affected Systems
The affected product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, distributed by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity, but the EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. Attackers can exploit it from any device with HTTP connectivity to the affected system, without authentication or user interaction. Given the lack of mitigation from the vendor besides a patch, the risk remains significant until the update is applied.
OpenCVE Enrichment