Impact
Vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to compromise the product. The flaw requires interaction from a different person and, while it resides in Hyperion, it can impact additional products as scope changes. Successful exploitation grants unauthorized update, insert, delete, or read access to a subset of the data, causing confidentiality and integrity breaches.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other product versions or vendors are listed.
Risk and Exploitability
The CVSS base score is 6.1, indicating moderate severity. No KEV listing and an EPSS score of less than 1% indicates a low exploitation probability. The attack vector is network-based HTTP, and the vulnerability requires UI interaction from someone other than the attacker, implying a social engineering component. Because the scope changes, the impact could extend beyond Hyperion to other components of the product suite.
OpenCVE Enrichment