Impact
The vulnerability is a flaw in the installation and configuration of Oracle Hyperion Infrastructure Technology that allows a low‑privileged local user to gain complete control of the application. Successful exploitation can breach confidentiality, integrity, and availability, effectively allowing the attacker to take over the system. Improper access control and incorrect permission assignment for sensitive resources are indicated by the weakness, and it is represented by a CVSS 3.1 vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, specifically the Installation and Configuration component, is affected as noted in the Oracle security advisory. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity. The EPSS score is less than 1 percent, showing a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local logon access to a server running the product; no network or remote interaction is required. If an attacker succeeds, they can obtain full control of the application, compromising all data and functions.
OpenCVE Enrichment