Impact
The Oracle Hyperion Infrastructure Technology installation and configuration component contains a missing access control flaw that allows a user who has already logged on with high privileges to modify, delete, or insert data. An attacker can also trigger a partial denial of service against the application. The vulnerability does not enable privilege escalation; it simply extends the capabilities of an existing high‑privileged account, leading to data tampering and limited availability disruption.
Affected Systems
Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is affected. The product is provided by Oracle Corporation and is the only product impacted by this advisory.
Risk and Exploitability
The CVSS 3.1 base score of 3.0 indicates a low overall severity, but it highlights integrity and availability impacts. The EPSS score is less than 1%, suggesting a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires local access (AV:L) and a high‑privilege account (PR:H), exploitation is limited to users who already have elevated permissions on the system, reducing the overall threat exposure but still posing a risk to the data integrity of the installed system.
OpenCVE Enrichment