Impact
A flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology allows an attacker to connect over HTTP without any authentication and access critical data. This vulnerability permits unauthorized reading or full access to all data exposed by the application, potentially leading to confidentiality loss. The weakness involves authentication bypass and improper authorization controls.
Affected Systems
Oracle Corporation Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, as disclosed by Oracle in their August 2026 security advisory. No other impacted versions are mentioned.
Risk and Exploitability
The attack vector is network-based over HTTP, reachable to anyone with network access to the host. The CVSS 3.1 base score of 7.5 indicates a high confidentiality impact. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV, so current exploitation activity is unknown, but the ease of exploitation suggests potential risk.
OpenCVE Enrichment