Sceawere

Vulnerability Detail

CVE-2026-70962UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-08-18T21:17:54.733Z",
  "pubdate": "2026-08-18T21:17:54.733Z",
  "executiveSummary": "An unauthorized read access vulnerability has been identified within the Oracle Hyperion Infrastructure Technology product, specifically affecting the Installation and Configuration component in version 11.2.25.0.000. This security flaw enables a low-privileged local attacker to compromise the targeted software by gaining unauthorized read access to a subset of sensitive data accessible by the application infrastructure. The vulnerability is classified with a CVSS 3.1 Base Score of 3.3, reflecting a limited impact exclusively targeting data confidentiality without affecting system integrity or availability. Exploitation requires physical or remote interactive logon capabilities to the underlying infrastructure where the affected Oracle Hyperion component executes, coupled with low privileges on the host operating system. The risk implication centers on the potential exposure of restricted data subsets, which could aid an adversary in performing subsequent reconnaissance phases or uncovering auxiliary sensitive information stored within the operational environment. Given the local access requirement, mitigation strategies should focus on enforcing strict host-based access controls, hardening operating system permissions, and applying official vendor patches as supplied by Oracle.",
  "technicalDetails": "The vulnerability resides within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, allowing low-privileged authenticated local users to extract sensitive data subsets. The root cause stems from improper access control enforcement or overly permissive file system and resource permissions configured during or after the installation process. Because the affected software manages critical enterprise performance management infrastructure, improper isolation of configuration data or runtime artifacts allows local users to read files and data structures they should normally be restricted from accessing.\nThe attack vector is strictly local (AV:L), meaning the adversary must already possess valid credentials and an interactive or programmatic logon session on the host operating system where the Oracle Hyperion Infrastructure Technology instance executes. Attack complexity is low (AC:L), requiring no specialized race conditions, memory corruption techniques, or complex cryptographic manipulation. Privilege requirements are low (PR:L), as standard, non-administrative local user accounts can initiate the attack. User interaction is not required (UI:N), and the scope remains unchanged (S:U).\nThe step-by-step attack flow initiates when the low-privileged attacker establishes a session on the host machine hosting the vulnerable Oracle Hyperion Infrastructure Technology deployment. Leveraging standard operating system utilities or custom scripts, the attacker navigates to the installation directories or data repositories managed by the Installation and Configuration component. Due to inadequate permission scoping on sensitive configuration files, logs, or data stores, the attacker bypasses logical boundaries to read restricted information. The payload behavior is passive in nature, manifesting purely as unauthorized read access (C:L) rather than active code execution, privilege escalation, or denial of service. The post-exploitation impact is constrained to the confidentiality domain, where the harvested data subset may expose internal architectural details, operational parameters, or sensitive business metrics that facilitate further target enumeration."
}
CVE-2026-70962: Oracle Hyperion Infrastructure Technology Information Disclosure Vulnerability (LOW Severity, CVSS: 3.3) - Sceawere