Sceawere
Vulnerability Detail
CVE-2026-70972UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Infrastructure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Infrastructure Technology
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-08-18T21:17:55.870Z",
"pubdate": "2026-08-18T21:17:55.870Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Hyperion Infrastructure Technology product, specifically within the Installation and Configuration component. The affected supported version is 11.2.25.0.000. This vulnerability is categorized as difficult to exploit, requiring specific attack conditions and high complexity.\nAn attacker must possess low privileges and network access via the HTTP protocol to successfully target the system. Successful exploitation does not affect system availability, but it grants the adversary unauthorized read, write, creation, and deletion capabilities over critical data, or potentially complete access to all data accessible by Oracle Hyperion Infrastructure Technology.\nThe risk implications include severe data integrity and confidentiality breaches, as unauthorized entities can manipulate or exfiltrate sensitive enterprise information managed within the application infrastructure. The CVSS 3.1 base score is 6.8, reflecting significant impacts on confidentiality and integrity with no direct impact on system availability.",
"technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The attack vector is network-based (AV:N), allowing remote adversaries with HTTP network connectivity to interact with the vulnerable service endpoints.\nThe attack complexity is rated as high (AC:H), indicating that successful exploitation requires specific preconditions, precise timing, or configuration nuances that make automated or straightforward exploitation difficult to achieve. Furthermore, the attacker must authenticate against the system with low privileges (PR:L), meaning an internal user account or compromised low-privileged credential set is mandatory to initiate the attack sequence.\nUser interaction is not required (UI:N), allowing the attack to be executed programmatically once the preliminary conditions are met. The attack scope remains unchanged (S:U), meaning the impact is constrained within the security boundary of the vulnerable Oracle Hyperion Infrastructure Technology component rather than cascading to underlying host resources.\nThe step-by-step attack flow begins with the low-privileged attacker establishing an HTTP network connection to the targeted Oracle Hyperion Infrastructure Technology service. Leveraging the specific weaknesses in the Installation and Configuration component, the attacker crafts specialized HTTP requests designed to bypass intended access controls. Due to insufficient validation or authorization checks within the targeted component, the server processes the request and grants the attacker unauthorized operational capabilities.\nPost-exploitation impacts involve severe confidentiality and integrity violations (C:H/I:H/A:N). The attacker can execute unauthorized creation, modification, and deletion of critical data structures, or achieve complete read access to sensitive datasets accessible by the Oracle Hyperion Infrastructure Technology application."
}