Impact
The flaw is an Access Control weakness (CWE-284) in the installation and configuration component of Oracle Hyperion Infrastructure Technology. A low-privileged attacker who can reach the system over the network via HTTP may exploit the defect to create, delete, or modify critical data and to gain unauthorized full access to all data exposed by the application, thereby compromising confidentiality and integrity.
Affected Systems
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, supplied by Oracle Corporation as part of the Hyperion suite, is affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.8 indicates moderate overall risk with high confidentiality and integrity impact. Exploitation requires network access, low privilege, and no user interaction, which lowers the overall threat. The EPSS score is below 1%, signifying a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack path, inferred from the description, involves sending crafted HTTP requests to exposed configuration endpoints to bypass access controls.
OpenCVE Enrichment