Impact
The vulnerability exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology. Based on the description, it is inferred that an attacker can exploit an injection flaw in SQL handling over the network. Successful exploitation allows the attacker to create, delete, or modify critical data and gain unauthorized read access to all data available to the application, thereby compromising confidentiality and integrity of the system.
Affected Systems
Affected product: Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 from Oracle Corporation. No other versions or products are explicitly listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score is 6.5, indicating a medium severity with a network attack vector, low complexity, high privileges required, no user interaction, and high impact on confidentiality and integrity. The EPSS score is less than 1%, indicating that the risk of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a high-privileged account and network connectivity to the Oracle Hyperion service, making the exploitation conditionally difficult but still possible for sufficiently privileged attackers. The overall risk is moderate, but remediation is still warranted due to the potential for significant data compromise.
OpenCVE Enrichment