CVE-2026-70962: Low severity Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already have low-privileged access and be able to log on to the infrastructure where Oracle Hyperion Infrastructure Technology runs. The vulnerability is locally exploitable and does not require user interaction.
What is the impact of a successful attack?
A successful attacker can gain unauthorized read access to a subset of data accessible to Oracle Hyperion Infrastructure Technology. The provided information indicates no integrity or availability impact.
Which version is identified as affected?
The affected supported version identified is 11.2.25.0.000.