Impact
A network‑based vulnerability in the Oracle Hyperion Infrastructure Technology Installation and Configuration component allows an entity with low privileges to create, delete, or modify critical data and to gain unauthorized access to all accessible data. The impact includes complete loss of confidentiality and integrity of data managed by the product.
Affected Systems
Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates high severity, and the vector shows that the exploit requires network access over HTTP, a low‑privilege user, and high complexity. EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would send crafted HTTP requests to the vulnerable installation endpoints; successful exploitation would allow them to manipulate critical data and gain unauthorized data access, impacting the confidentiality and integrity of the system.
OpenCVE Enrichment