Impact
The vulnerability resides in the installation and configuration component of Oracle Hyperion Infrastructure Technology and enables a low‑privileged network attacker to create, delete or modify critical data and to gain unauthorized access to all accessible data. The flaw is an improper access control weakness that results in confidentiality and integrity loss for the affected system.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology product, version 11.2.25.0.000, is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity with significant confidentiality and integrity impact. The attack vector is network (HTTP), with low attack complexity and privilege requirements. Although the EPSS score is below 1%, which shows a low current exploitation probability, the ease of exploitation via HTTP and the availability of a low‑privileged attacker make the risk noteworthy. The vulnerability is not listed in the CISA KEV catalog, but the potential for wide‑scale data breach warrants rapid remediation.
OpenCVE Enrichment