Impact
A local vulnerability exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology. The weakness is an access control flaw. An attacker who has low‑privilege access to the infrastructure on which Hyperion runs can modify the data by performing unauthorized update, insert, or delete operations. This results in a breach of data integrity, though confidentiality and availability remain unaffected.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The vulnerability specifically targets the installation and configuration part of that product.
Risk and Exploitability
The CVSS Base Score of 3.3 indicates a low‑severity integrity impact, and the EPSS score is less than 1%. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires local log‑on with low privileges, the likelihood of exploitation is limited to environments where privileged control is inadequately enforced. While the risk to the broader network is low, any compromised instance could be used to alter business data or disrupt reporting functions.
OpenCVE Enrichment