Impact
The vulnerability is an information disclosure flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology. An unauthenticated attacker who has logon access to the infrastructure hosting the product can read a subset of data that should remain confidential, but cannot modify or delete it.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. This impacts installations of the said product deployed on Oracle infrastructure environments.
Risk and Exploitability
The CVSS v3.1 base score is 4.0, reflecting a low confidentiality impact with no integrity or availability effects. EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires local access; the attacker must already have logon privileges to the infrastructure where the product runs, suggesting that the risk is primarily to systems with insufficient local security controls.
OpenCVE Enrichment