Impact
The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. It permits an attacker who has only low privileges and network access via HTTP to gain unauthorized access to critical data, and to modify or delete data within the system. The flaw results in a high confidentiality impact and a low integrity impact, enabling the attacker to read, insert, update, or delete data that the attacker should not be able to reach.
Affected Systems
Oracle Corporation’s Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. System administrators should verify that this version or earlier build is in use.
Risk and Exploitability
The CVSS score of 7.1 reflects the potential for significant confidentiality loss and limited integrity impact. The low privilege requirement and lack of user interaction mean the attack is feasible with only network connectivity to the Hyperion instance, raising concern for environments with open public access. Though not yet seen in the CISA KEV catalog, the nature of the vulnerability—improper access control in a critical component—suggests that attackers could mount similar exploits once knowledge of the issue spreads.
OpenCVE Enrichment