Impact
A flaw in the installation and configuration process of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 gives a high‑privileged local attacker the ability to modify, insert, or delete data that the application can access, and to trigger a partial denial of service. The vulnerability does not allow remote code execution or privilege escalation beyond what the attacker already possesses, but it undermines the confidentiality, integrity, and availability of the application’s data and the service’s uptime.
Affected Systems
The affected product is Oracle Hyperion Infrastructure Technology from Oracle Corporation. Only version 11.2.25.0.000 is listed as vulnerable. No other versions are mentioned, and the weakness is tied to the installation and configuration component.
Risk and Exploitability
The CVSS v3.1 base score is 3.0, reflecting low overall severity with modest integrity and availability impacts. EPSS is not available, indicating no publicly known high likelihood of exploitation. The flaw requires local physical or virtual console access and high‑privilege credentials to the host where the product runs, meaning a targeted insider or attacker with elevated local rights. The vulnerability is not in the CISA KEV catalog, so there is no evidence of ongoing exploitation in the wild. Nonetheless, any environment running the affected release should treat this as a notable risk when local high‑privileged accounts are present on the same infrastructure.
OpenCVE Enrichment