Impact
The flaw exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. An attacker who can log onto the host with a low‑privileged account can exploit the vulnerability to read all data that the application makes available, resulting in a high confidentiality impact. Because the flaw changes the affected scope, other products that rely on the same infrastructure may also be exposed. The weakness is a lack of proper authorization checks that allow unauthorized read access to confidential information.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, as distributed by Oracle Corporation, is affected. Systems running this version on a host where local low‑privileged users can log on or execute code are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity, with high confidentiality impact but limited attacker privileges. The EPSS score of less than 1% suggests that the probability of exploitation is currently low, and the issue is not listed in the CISA KEV catalog. Nonetheless, environments that allow low‑privileged local access remain at risk because the vulnerability is easily exploitable once such an account exists. The likely attack vector is local: a low‑privileged account that can execute code on the host bypasses application‑level checks and exposes all accessible data.
OpenCVE Enrichment