Impact
A flaw in the installation and configuration of Oracle Hyperion Infrastructure Technology allows a local user with low privileges to compromise the application and gain unauthorized access to critical data. The vulnerability is an improper access control issue that can lead to confidentiality loss without impacting integrity or availability.
Affected Systems
Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. No other vendors or products are affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.5 indicates moderate severity. Exploitation requires local access and low privilege authentication, but the vulnerability is easily exploitable once the attacker has logon to the infrastructure. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a local configuration error that an attacker can manipulate to read or retrieve confidential data.
OpenCVE Enrichment