Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the installation and configuration component of Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker with network access via HTTP to read a subset of data stored by the application. The vulnerability is a confidentiality issue, specifically an information exposure through lack of access control and improper access control. The flaw requires no credentials and can be exploited remotely without user interaction.

Affected Systems

Oracle Corporation’s Hyperion Infrastructure Technology product is affected. The only version identified as vulnerable is 11.2.25.0.000. No other product variants or versions are listed in the advisory.

Risk and Exploitability

The moderate CVSS base score of 5.3 indicates a non‑critical, but still useful, vulnerability for adversaries seeking data exposure. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalogue. Based on the description, the attack vector is a straightforward unauthenticated network request over HTTP; no prior authentication, privilege escalation, or physical access is required.

Generated by OpenCVE AI on August 26, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a later, non‑vulnerable version of Oracle Hyperion Infrastructure Technology
  • Restrict external network reach to the Hyperion HTTP interface with firewalls or access control lists to limit exposure to trusted hosts
  • Configure or enforce authentication mechanisms on the Hyperion installation and configuration components to prevent unauthenticated access

Generated by OpenCVE AI on August 26, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Information Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network-Based Information Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Read Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Read Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:47.505Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62579

cve-icon Vulnrichment

Updated: 2026-08-26T17:31:07.056Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:09.937

Modified: 2026-08-26T18:16:50.920

Link: CVE-2026-62579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T06:00:12Z

Weaknesses