Impact
Oracle Hyperion Infrastructure Technology is vulnerable to an access control flaw that allows attackers with low‑privilege credentials who can reach the service over HTTP to create, delete or modify critical data and to trigger the application to hang or crash repeatedly, thereby compromising data integrity and system availability.
Affected Systems
Only the Oracle Hyperion Infrastructure Technology product version 11.2.25.0.000 from Oracle Corporation is affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects significant integrity and availability impacts, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely over HTTP without special privileges, making exposed installations at appreciable risk.
OpenCVE Enrichment