Impact
A low‑privileged user who can log on to the system where Oracle Hyperion Infrastructure Technology runs may exploit a flaw in the installation and configuration component. The vulnerability allows the attacker to read a subset of data made available by the application, leading to confidentiality violations. The CVSS 3.1 base score of 3.3 reflects that the impact is limited to confidentiality only, with an attack vector of local access, low complexity, and low privileges required.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The vulnerability is specific to the installation and configuration functionality of this product.
Risk and Exploitability
The CVSS score of 3.3 indicates a modest risk, and the EPSS score of <1% indicates a very low likelihood of exploitation in the general population. Because the vulnerability requires local logon and low privileges, the exposure is limited to users with access to the host. The vulnerability is not listed in the CISA KEV catalog, further indicating a lower exploitation priority. An attacker could read sensitive data available to the application but cannot modify or execute code on the system.
OpenCVE Enrichment