Sceawere

Vulnerability Detail

CVE-2026-70963UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Flaw

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-08-18T21:17:54.847Z",
  "pubdate": "2026-08-18T21:17:54.847Z",
  "executiveSummary": "An input-based security vulnerability has been identified within the Oracle Hyperion Infrastructure Technology product, specifically residing in the Installation and Configuration component. The affected supported version is strictly limited to 11.2.25.0.000. This security issue is characterized as difficult to exploit, requiring specific environmental or transactional conditions to achieve successful execution by a threat actor. The vulnerability allows an attacker with low privileges and network access via the HTTP protocol to compromise the integrity and confidentiality of the targeted system. Successful exploitation does not result in a complete system takeover or denial of service, but it does grant unauthorized actors the capability to perform insert, update, or delete operations on specific accessible data, alongside unauthorized read access to a subset of information housed within Oracle Hyperion Infrastructure Technology. The resulting CVSS 3.1 Base Score is 4.2, driven by low confidentiality and integrity impacts, with no availability disruption. The attack vector is network-based, requiring high attack complexity, low privilege requirements, and no user interaction, maintaining an unchanged security scope.",
  "technicalDetails": "The vulnerability affects the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The root cause stems from insufficient access controls, validation mechanisms, or authorization checks within the targeted component, which fails to adequately restrict data manipulation and retrieval operations for authenticated sessions possessing limited privileges. Because the attack vector is network-based utilizing the HTTP protocol, an adversary must possess valid low-level credentials to authenticate against the vulnerable service, satisfying the low privilege requirement defined in the CVSS vector (PR:L). Although network accessibility is required (AV:N), the attack complexity is rated as high (AC:H), indicating that exploitation is not trivial and likely requires precise timing, specific configuration states, or race conditions to successfully bypass existing logical barriers within the application layer. The attack flow begins with the low-privileged attacker establishing an HTTP connection to the vulnerable Oracle Hyperion Infrastructure Technology endpoint. The attacker then crafts specific requests designed to interact with the Installation and Configuration component. Due to inadequate server-side enforcement of authorization policies, the application processes these requests despite the user lacking the requisite administrative or high-level functional permissions. Consequently, the payload behavior manifests as unauthorized data operations, allowing the attacker to bypass segregation of duties or role-based access control boundaries. The post-exploitation impact is strictly confined to data-level consequences, resulting in unauthorized read access to a subset of sensitive data, as well as unauthorized insert, update, or delete access to accessible data stores managed by the application. The vulnerability does not allow for arbitrary code execution, system-level command injection, or denial of service conditions against the host operating system (A:N, S:U)."
}
CVE-2026-70963: Oracle Hyperion Infrastructure Technology Flaw (MEDIUM Severity, CVSS: 4.2) - Sceawere