Impact
This vulnerability exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. An attacker who can reach the server over the network using HTTP can exploit the lack of authentication controls. Based on the description, it is inferred that the weakness is a failure to enforce authentication and authorization before allowing access to data, which permits an unauthorized read of a subset of data normally protected, resulting in partial disclosure of confidential information. The flaw is therefore an information‑exposure vulnerability with a moderate CVSS score.
Affected Systems
The affected deployment is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. This is the only supported version listed in the advisory. No other versions are indicated as affected in the current information. Administrators should verify that their installed instance matches this version to assess exposure.
Risk and Exploitability
The CVSS v3.1 score of 5.3 classifies the issue as a medium‑severity information‑disclosure flaw. The likely attack vector is network‑based HTTP, as the description states the attacker needs network access via HTTP and the vulnerability does not require user interaction or privileged access. EPSS data indicates a very low but non‑zero exploitation probability (less than 1%) and the vulnerability is not yet listed as an actively exploited threat in CISA’s KEV catalog. The ease of exploitation—unrestricted unauthenticated HTTP access—means that once a patch becomes available, the risk to exposed installations could increase rapidly.
OpenCVE Enrichment