Impact
The vulnerability exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology. An attacker with low-privileged network access over HTTP can exploit the flaw to bypass normal access controls, allowing them to execute arbitrary code on the system. Successful exploitation results in a full takeover of Oracle Hyperion, compromising confidentiality, integrity, and availability. The weakness is categorized as an access control flaw (CWE-284).
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is identified as affected. No other versions or products are reported to be impacted by this specific flaw.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a network-based interaction over HTTP with a low-privileged attacker. If exploited, the attacker can achieve full control of the system, underscoring the need for immediate remediation.
OpenCVE Enrichment