Impact
A flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology allows an attacker with low privileges who can reach the system over HTTP to obtain unrestricted access to all data exposed by the platform. The vulnerability is classified as a confidentiality breach, with a CVSS 3.1 base score of 6.5, indicating moderate severity but a significant impact on confidential information.
Affected Systems
Oracle Corporation’s Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The weakness is located in the installation and configuration module of this product and permits a non‑privileged adversary who can reach the system over HTTP to compromise the system and read any data accessible through the platform.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate overall risk with a high confidentiality impact. The EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation in the wild. Attackers can exploit this weakness by sending crafted HTTP requests to the vulnerable component, requiring only low privileges and no special preconditions, making it reachable from an intranet or via web‑crawler activity. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment