CVE-2026-62570: Low severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Exploitation requires an attacker who already has high privileges and a logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes. The vulnerability is locally exploitable and has high attack complexity.
Which version is identified as affected?
The affected supported version is 11.2.25.0.000.
What could a successful attacker do?
A successful attack could allow unauthorized update, insert, or delete access to some accessible data, and could cause a partial denial of service.