Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Hyperion Infrastructure Technology’s Common Events component allows an attacker with low privileges and network access via SQL to compromise the system. Successful exploitation can lead to full takeover of the application, compromising confidentiality, integrity, and availability across the infrastructure.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other versions or vendors are listed.

Risk and Exploitability

The CVSS v3.1 score of 7.5 indicates high severity, with impacts on all three core security dimensions. The attack vector is network-based, requiring only low privileged access and no user interaction. While the EPSS score is not available, the lack of a KEV listing implies no known exploitation yet. Nonetheless, the potential for a full compromise warrants immediate attention.

Generated by OpenCVE AI on August 19, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch for Oracle Hyperion Infrastructure Technology 11.2.25.0.000 as soon as it is released.
  • Restrict database access so that only privileged accounts with proper authorization can reach the affected component; remove or elevate network permissions for accounts that need only low privileges.
  • Audit the application’s SQL handling and implement parameterized queries or other input validation techniques to eliminate potential injection points.

Generated by OpenCVE AI on August 19, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploit Allows Takeover of Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-89

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:17.787Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62481

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:03.530

Modified: 2026-08-18T21:17:03.530

Link: CVE-2026-62481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')