CVE-2026-62553: Medium severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Hyperion Infrastructure Technology (Installation and Configuration)to a version that resolves this vulnerability.Fixed in 11.2.25.0.000
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 are affected. Exploitation requires a low-privileged attacker to have a logon to the infrastructure where the product runs, so it is not described as remotely exploitable without local access.
What could an attacker gain if exploitation succeeds?
A successful attack can provide unauthorized access to critical data or complete access to all data accessible to Oracle Hyperion Infrastructure Technology. The stated impact is confidentiality only; integrity and availability impacts are not identified.
Does exploiting this issue require user interaction or elevated privileges?
No user interaction is required. The attacker needs only low privileges and a logon to the affected infrastructure; the attack complexity is low.