Impact
The vulnerability exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. An attacker who gains local access to the infrastructure running the application can, with the cooperation of a second person, compromise the application even without any initial authentication. Successful exploitation allows the attacker to create, delete or modify any critical data and to gain unauthorized access to all data the application can access, breaching both confidentiality and integrity of the system’s information.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 by Oracle Corporation. The flaw applies to installations where the application runs on infrastructure that a user can log on to locally.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 categorizes this vulnerability as medium severity. Local access is required, the attack vector is local (AV:L) with high attack complexity and no privileges needed; however the attacker must provide user interaction (UI:R). An EPSS score of < 1% indicates a very low exploitation probability, but still implies the vulnerability can be exploited under the right conditions. The vulnerability is not listed in the CISA KEV catalog. Therefore, the risk level hinges on the presence of local attackers and the degree of physical or local network security controls; when these conditions exist, the flaw can lead to significant data tampering or disclosure.
OpenCVE Enrichment