CVE-2026-62584: Medium severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 are affected. Exploitation requires access to the infrastructure where the product executes, so it is a local-access issue rather than a remotely reachable one.
Does an attacker need an Oracle Hyperion account or user interaction to exploit it?
No product credentials or user interaction are required. The attacker must be able to log on to the underlying infrastructure, but the CVSS vector indicates no privileges are required once that access is available.
What is the expected impact of a successful attack?
A successful attack can provide unauthorized read access to a subset of data accessible to Oracle Hyperion Infrastructure Technology. The stated impact is limited to confidentiality; integrity and availability impacts are not identified.