Impact
The Vulnerability in Oracle Hyperion Infrastructure Technology lies in the installation and configuration component, allowing an unauthenticated attacker who can reach the system over an HTTP network connection to compromise the service. This vulnerability corresponds to CWE‑601, an open redirect weakness. The exploit requires a separate human actor—someone other than the attacker—to interact with the system, after which the attacker can achieve full takeover of the Oracle Hyperion instance. The impact spans confidentiality, integrity and availability, as identified by the CVSS score of 9.6, and the vector indicates a scope change, meaning privileges can be increased within the same realm.
Affected Systems
Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, a product of Oracle Corporation. The vulnerability applies to this specific build; no other versions are listed as affected.
Risk and Exploitability
With a CVSS Base Score of 9.6 the vulnerability is classified as Critical. The EPSS score of <1% indicates a very low exploitation probability, and it is not listed in the CISA Known Exploited Vulnerabilities catalog, but the high score and the fact that it requires only unauthenticated network access over HTTP raise the likelihood that attackers will target the affected infrastructure. Successful exploitation would give the attacker full control of the Hyperion service, potentially affecting other connected products due to the scope change. The dependency on external human interaction may reduce the immediacy of exploitation, yet once a user interacts, compromise is typically straightforward.
OpenCVE Enrichment