CVE-2026-62575: Medium severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Is network-only access sufficient to exploit this issue?
No. The CVSS vector identifies the attack vector as local, so the attacker needs access to the infrastructure where the product executes.
Does successful exploitation affect system integrity or availability?
The stated impact is confidentiality only. The CVSS vector assigns high confidentiality impact and no integrity or availability impact.