Impact
The Oracle Hyperion Infrastructure Technology product contains an easily exploitable flaw in its installation and configuration components that can be triggered over HTTP. A low‑privileged attacker who can reach the service can use the vulnerability to gain full control of the Hyperion environment, resulting in immediate compromise of confidentiality, integrity, and availability.
Affected Systems
Affected systems are Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. Oracle Hyperion is the vendor, and the vulnerability applies to all deployments of this specific release. No other Oracle products are listed as impacted in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity. With an attack vector of network through HTTP and a low attack complexity, the probability of exploitation is considered high, although the EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Any exposed instance of the affected version poses a significant risk.
OpenCVE Enrichment