Impact
This vulnerability arises in the installation and configuration component of Oracle Hyperion Infrastructure Technology. A remotely reachable HTTP endpoint can be abused by an attacker with only low privileges to execute a successful attack. The result is a full compromise of the Oracle Hyperion instance, giving the attacker control that can lead to complete takeover. The impact is severe, affecting confidentiality, integrity and availability.
Affected Systems
Affected systems are Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. The vulnerability is described as present in this specific version and no other versions are listed in the CNA data. The CPE string confirms the affected software edition.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 reflects a high overall severity. The attack vector is network‑based (HTTP) and requires only low privileges with no user interaction, indicating that the vulnerability is easily exploitable. The EPSS score is < 1%, which indicates an extremely low but non‑zero probability that the vulnerability is being actively exploited. The vulnerability is not listed in the CISA KEV catalog, but the lack of a KEV entry does not mitigate the risk of a successful compromise.
OpenCVE Enrichment