Impact
A vulnerability exists in Oracle Hyperion Infrastructure Technology that allows an unauthenticated attacker who can reach the system over HTTP to compromise the application. This is a CWE-284 authorization flaw. The impact includes unauthorized update, insert, or delete of data, as well as unauthorized read of a subset of the data. The CVSS 3.1 score of 6.1 reflects moderate confidentiality and integrity loss with the need for a user interaction part of the exploitation process.
Affected Systems
Version 11.2.25.0.000 of Oracle Hyperion Infrastructure Technology is affected. No other products or versions are listed.
Risk and Exploitability
The vulnerability is reachable via HTTP from the network and requires no prior authentication but does need a person other than the attacker to interact for a successful compromise. The CVSS vector indicates Network attack, low complexity, none privileges, user interaction required, and scope change. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation at this time but the moderate CVSS indicates a non‑negligible risk.
OpenCVE Enrichment