Impact
A flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology allows a low-privileged user who has logged onto the host to read data that it otherwise would not be able to access. The vulnerability is rooted in improper access control and insufficient permission checks, permitting disclosure of sensitive information while leaving integrity and availability untouched.
Affected Systems
The product affected is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. Users with local logon rights but not full administrative privileges can exploit the flaw during the installation and configuration phase, potentially accessing all data exposed by the product.
Risk and Exploitability
The CVSS v3.1 base score of 5.5, generated from a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H, indicates moderate severity limited to confidentiality. The EPSS score of < 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Because the attack requires local access with low privileges and no user interaction, any non-administrator who logs onto the machine could potentially activate the disclosure path, making the risk relatively high in environments where local logons are granted broadly.
OpenCVE Enrichment