Impact
The vulnerability in Oracle Hyperion Infrastructure Technology 11.2.25.0.000 allows an unauthenticated attacker with network access over TLS to bypass authentication and gain unauthorized access to critical data, including the ability to update, insert or delete records. The flaw is an authentication bypass, classified as an improper access control weakness. Successful exploitation can lead to unauthorized disclosure of confidential information and unauthorized modification of data, posing a moderate confidentiality and integrity risk to the affected system.
Affected Systems
Affected systems are all installations of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 deployed by Oracle Corporation. Only this version is confirmed to be impacted; other versions are not known to be vulnerable at this time.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity vulnerability that requires network exposure and no authentication. The EPSS score of <1% indicates a very low exploitation probability, and the lack of a CISA KEV listing suggests no widely observed exploitation yet. However, because the attack path requires only TLS network connectivity and no privileged credentials, the potential for exploitation remains significant, especially in environments where Hyperion is directly exposed to untrusted networks.
OpenCVE Enrichment