Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access via HTTP can read a subset of data exposed by the Oracle Hyperion Infrastructure Technology installation. The vulnerability resides in the Installation and Configuration component and does not require authentication, allowing the attacker to gain information that may be confidential. The impact is limited to confidentiality; integrity and availability are not affected. The weakness is an improper access control flaw that permits unauthorized data read access.

Affected Systems

The affected product is Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, as noted in the Oracle security advisory. Only this specific version of the Hyperion product is vulnerable; no other versions or components are mentioned.

Risk and Exploitability

The CVSS base score of 5.3 reflects moderate potential for data exposure. The exploit is network‑based and requires no prior authentication, making it easily exploitable over HTTP. EPSS is not available, so the current exploitation probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog, but because it allows unauthenticated read access, it should be considered a moderate to high operational risk for environments where Sensitive data is handled.

Generated by OpenCVE AI on August 19, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade for Oracle Hyperion Infrastructure Technology 11.2.25.0.000 as specified in the Oracle security advisory
  • Restrict or disable HTTP access to the Hyperion web interface for users who do not need it, using firewall rules or internal network segmentation
  • Verify that the underlying installation enforces proper authentication and access controls, ensuring that only authorized personnel can view or query data via the web interface

Generated by OpenCVE AI on August 19, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Hyperion Infrastructure Allows Data Exposure
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:21.094Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62510

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:04.707

Modified: 2026-08-18T21:17:04.707

Link: CVE-2026-62510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control