Impact
This vulnerability allows a low‑privileged attacker who can log on to the infrastructure hosting Oracle Hyperion Infrastructure Technology to compromise the application. Successful exploitation leads to unauthorized access to critical data or full access to all Hyperion‑accessible data. The weakness is an improper authorization control in the installation and configuration component, resulting in a confidentiality impact only, as reflected by the CVSS 3.1 vector.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other versions or products are listed.
Risk and Exploitability
The CVSS base score of 5.5 indicates a moderate risk level. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker only needs to be logged into the infrastructure where Hyperion runs and possess low privileges, requiring no user interaction. The threat primarily concerns internal adversaries or compromised accounts who can exploit the misconfigured installation to read protected data.
OpenCVE Enrichment