Impact
The flaw exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology and enables a low‑privileged attacker with network access through HTTP to perform unauthorized updates, inserts, deletions, or read operations on data that should be protected. This results in a compromise of data confidentiality and integrity as the attacker can alter or disclose sensitive information. The weakness is a lack of proper access control, reflected in a CVSS 3.1 score of 4.2.
Affected Systems
Affected equipment consists of Oracle Hyperion Infrastructure Technology supplied by Oracle Corporation, specifically version 11.2.25.0.000 as listed in the CVE data.
Risk and Exploitability
The reported CVSS base score of 4.2 signifies moderate risk; availability is unaffected. The EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The simplest attack route involves reaching the HTTP endpoint from an external or internal network; a remote attacker with a low‑privileged account can leverage the missing authorization controls to read or modify data.
OpenCVE Enrichment