Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to compromise the product. The flaw requires interaction from a different person and, while it resides in Hyperion, it can impact additional products as scope changes. Successful exploitation grants unauthorized update, insert, delete, or read access to a subset of the data, causing confidentiality and integrity breaches.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other product versions or vendors are listed.

Risk and Exploitability

The CVSS base score is 6.1, indicating moderate severity. No KEV listing and an EPSS score of less than 1% indicates a low exploitation probability. The attack vector is network-based HTTP, and the vulnerability requires UI interaction from someone other than the attacker, implying a social engineering component. Because the scope changes, the impact could extend beyond Hyperion to other components of the product suite.

Generated by OpenCVE AI on August 26, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Hyperion Infrastructure Technology 11.2.25.0.000 when it becomes available.
  • Restrict HTTP access to the Hyperion server using network segmentation or firewall rules to allow only trusted IP addresses.
  • Enforce authentication on all installation and configuration interfaces and ensure role‑based access controls are properly configured.
  • Provide user awareness training to prevent unauthorized interactions that could trigger the vulnerability.

Generated by OpenCVE AI on August 26, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Data Modification in Oracle Hyperion

Tue, 25 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Tampering in Oracle Hyperion Infrastructure
Weaknesses CWE-639

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 21 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Tampering in Oracle Hyperion Infrastructure
Weaknesses CWE-639

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T18:03:32.758Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62568

cve-icon Vulnrichment

Updated: 2026-08-25T17:56:34.568Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:08.560

Modified: 2026-08-25T18:17:57.957

Link: CVE-2026-62568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:30:16Z

Weaknesses