Impact
The vulnerability exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology and can be exploited by an attacker who has system‑level access on the host where the software runs. Successful exploitation permits an attacker to insert, update, or delete data stored in the application and to cause a partial denial of service. The impact is limited to integrity and availability of the affected data and is presented in the CVSS vector as low confidentiality impact, low integrity impact and low availability impact.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The vulnerability is only known to affect this specific release of the product from Oracle.
Risk and Exploitability
The CVSS 3.1 base score of 3.4 reflects the low severity of the flaw. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires a local user with high privileges on the host, so the likely attack vector is local access by an account that the application runs under. Because the vulnerability is not remote, the risk depends on the privileges of the local accounts used to run Hyperion and on the security posture of the host system.
OpenCVE Enrichment