CVE-2026-62509: Medium severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
How can I determine whether my deployment is within the affected scope?
The affected supported version is Oracle Hyperion Infrastructure Technology 11.2.25.0.000, specifically the Common Events component.
What access does an attacker need to exploit this issue?
An attacker needs network access to the target over HTTP. No authentication, prior privileges, or user interaction are required, and the attack complexity is low.
What is the expected impact of a successful attack?
A successful attack can provide unauthorized read access to a subset of data accessible through Oracle Hyperion Infrastructure Technology. The stated impact is limited to confidentiality; integrity and availability impacts are not identified.