Impact
A flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to read a subset of data stored by the application. The vulnerability is a confidentiality issue, specifically an information exposure through lack of access control and improper access control. The flaw requires no credentials and can be exploited remotely without user interaction.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology product is affected. The only version identified as vulnerable is 11.2.25.0.000. No other product variants or versions are listed in the advisory.
Risk and Exploitability
The moderate CVSS base score of 5.3 indicates a non‑critical, but still useful, vulnerability for adversaries seeking data exposure. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalogue. Based on the description, the attack vector is a straightforward unauthenticated network request over HTTP; no prior authentication, privilege escalation, or physical access is required.
OpenCVE Enrichment