Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-08-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 contains an implementation flaw in its installation and configuration component that fails to enforce proper authentication for HTTP requests. An unauthenticated attacker on the network can send specially crafted HTTP traffic to the affected system and perform data modifications (update, insert, delete) on any accessible data. The attacker also gains read access to some protected data and can trigger a partial denial of service that temporarily disrupts availability. Together, these capabilities compromise the confidentiality, integrity, and availability of the system as reflected in the CVSS scoring.

Affected Systems

The vulnerability is limited to Oracle Hyperion Infrastructure Technology, specifically the 11.2.25.0.000 release. Only users who run this version and expose the HTTP interface to a network are vulnerable, as the flaw resides in the installation and configuration manager. Affected developers and administrators should verify the installed version and confirm that no unpatched instances remain exposed.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high impact with ease of exploitation. The vulnerability requires network connectivity to the HTTP interface and does not require prior authentication, making it trivially exploitable. While no EPSS value is published, the lack of a KEV entry means no known active exploitation is reported, yet the exploit conditions are simple enough that a threat actor could abuse the flaw rapidly if the product remains publicly reachable. Prompt remediation is recommended given the clear path to unauthorized data alteration and service disruption.

Generated by OpenCVE AI on August 19, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a non‑affected version of Hyperion Infrastructure Technology.
  • Re‑configure the HTTP interface to restrict access to trusted networks or enforce authentication before any data‑related requests are processed.
  • Verify that the installation and configuration component correctly validates user credentials and incorporates hardened access control checks to prevent unauthenticated manipulation of data and services.

Generated by OpenCVE AI on August 19, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation and Partial Downtime in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:15.525Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62551

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:21.784Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:07.457

Modified: 2026-08-24T16:12:58.680

Link: CVE-2026-62551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses