Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Common Events component of Oracle Hyperion Infrastructure Technology. A low‑privileged attacker with network access can send crafted SQL statements that are executed with system privileges. Successful exploitation results in full takeover of the application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, from Oracle Corporation, is the only product and version listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 reflects high severity across all three core security dimensions. The attack vector is network‑based, requires low privileges and no user interaction. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, yet the potential for application takeover warrants urgent attention.

Generated by OpenCVE AI on August 24, 2026 at 22:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a fixed version of Oracle Hyperion Infrastructure Technology as soon as it is available.
  • Restrict network access to the database so that only accounts with appropriate privileges can reach the vulnerable component; consider removing or elevating network permissions for low‑privileged accounts.
  • Review and enforce proper input validation and access controls on the Common Events component to eliminate similar access‑control weaknesses.

Generated by OpenCVE AI on August 24, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title SQL Vulnerability Allows Low-Privilege Application Takeover in Oracle Hyperion Infrastructure Technology

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title SQL Vulnerability Allows Low-Privilege Application Takeover in Oracle Hyperion Infrastructure Technology

Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploit Allows Takeover of Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-89

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploit Allows Takeover of Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-89

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:23:04.789Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62481

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:58.065Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:03.530

Modified: 2026-08-25T16:10:27.017

Link: CVE-2026-62481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:15:13Z

Weaknesses