Sceawere

Vulnerability Detail

CVE-2026-70971UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:55.757Z",
  "pubdate": "2026-08-18T21:17:55.757Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Oracle Hyperion Infrastructure Technology product, specifically within the Installation and Configuration component in version 11.2.25.0.000. This security flaw allows a low-privileged remote attacker with network access via HTTP to compromise the affected system, leading to significant impacts on data confidentiality and integrity.\nSuccessful exploitation of this vulnerability can grant an unauthorized attacker complete or critical access to all accessible data within Oracle Hyperion Infrastructure Technology, alongside unauthorized capabilities to update, insert, or delete a subset of the accessible data. The vulnerability presents a severe risk to organizational data integrity and sensitive information assets, carrying a CVSS 3.1 Base Score of 7.1 with a vector indicating network attack vector, low attack complexity, low privilege requirements, and no user interaction.\nThe risk implications include potential data breaches, unauthorized data manipulation, and compromise of enterprise performance management infrastructure. Remediation requires applying the appropriate vendor-supplied updates and enforcing strict access controls to mitigate unauthorized network interactions.",
  "technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The root cause stems from insufficient access controls and improper validation of HTTP requests processed by the application layer during configuration and installation routines, allowing low-privileged authenticated users to bypass intended security boundaries.\nThe attack vector is network-based (AV:N), requiring the attacker to possess low privileges (PR:L) and network connectivity via the HTTP protocol to interact with the vulnerable Oracle Hyperion Infrastructure Technology endpoints. The attack complexity is rated as low (AC:L), and the exploit does not require user interaction (UI:N).\nThe step-by-step attack flow involves the malicious actor establishing an HTTP connection to the vulnerable Oracle Hyperion Infrastructure Technology instance. Utilizing low-privileged credentials, the attacker transmits crafted requests targeted at the Installation and Configuration component. Due to inadequate authorization checks within the affected component, the application fails to adequately validate whether the requesting entity possesses the necessary administrative or functional entitlements to access or modify specific data objects.\nUpon successful processing of the crafted HTTP requests, the payload behavior enables the attacker to read highly sensitive information, resulting in unauthorized access to critical data or complete access to all accessible data within the Oracle Hyperion Infrastructure Technology environment. Furthermore, the attacker gains unauthorized capabilities to perform data manipulation actions, specifically inserting, updating, or deleting a subset of the accessible data structures.\nThe post-exploitation impact is characterized by a high impact on confidentiality (C:H) and a low impact on integrity (I:L), with no availability disruption (A:N). This permits unauthorized data exfiltration and targeted data corruption within the affected Hyperion environment."
}
CVE-2026-70971: Oracle Hyperion Infrastructure Access Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere