Impact
The vulnerability is found in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. It can be exploited by a low privileged user that is logged on to the infrastructure where the product runs. Successful exploitation would allow that user to compromise the product and read critical data stored or managed by Oracle Hyperion Infrastructure Technology. The description clearly states that unauthorized access to critical data may result from a successful attack, indicating that the confidentiality of the data is the primary impact.
Affected Systems
Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. Only this specific version is listed as affected.
Risk and Exploitability
The CVSS 3.1 score of 4.7 reflects a medium severity with a local attack vector, high access complexity, low privilege, no user interaction, and scope unchanged. Confidentiality is impacted while integrity and availability are unaffected. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. According to the description, the attack requires the attacker to be logged into the environment and to have low privilege on the host; the vulnerability is described as difficult to exploit, which suggests that successful attacks are not trivial but still possible if necessary conditions are met.
OpenCVE Enrichment