CVE-2015-2572 describes an unspecified vulnerability within the Oracle Hyperion Smart View for Office component, affecting versions 11.1.2.5.216 and earlier when running on Windows. This local vulnerability allows an attacker to impact the confidentiality, integrity, and availability of the system through unknown vectors related to Core. With a CVSS score of 4.6, this vulnerability has a low attack complexity and requires local access, but can lead to partial loss of confidentiality, integrity, and availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor is it listed on the CISA KEV catalog. While no Metasploit or Nuclei modules exist, a proof-of-concept crash exploit (EDB-36783) is available on ExploitDB. Community discussion and media coverage for this CVE are virtually nonexistent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.1.2.5.216CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion_smart_view_for_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.