Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 26 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Physical Access Exploit Enables Full Control of Oracle Hyperion Infrastructure Technology | |
| Weaknesses | CWE-284 |
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hyperion Infrastructure Physical Access Vulnerability Allows Full System Takeover | |
| Weaknesses | CWE-284 |
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo |
Fri, 21 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hyperion Infrastructure Physical Access Vulnerability Allows Full System Takeover | |
| Weaknesses | CWE-284 |
Fri, 21 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted Physical Segment Access Enables Enterprise Takeover in Oracle Hyperion Infrastructure Technology | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted Physical Segment Access Enables Enterprise Takeover in Oracle Hyperion Infrastructure Technology | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle hyperion Infrastructure Technology |
|
| CPEs | cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle hyperion Infrastructure Technology |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:00:28.002Z
Updated: 2026-08-26T15:26:19.403Z
Reserved: 2026-07-14T14:54:48.740Z
Link: CVE-2026-62545
Updated: 2026-08-26T13:48:54.996Z
Status : Modified
Published: 2026-08-18T21:17:07.067
Modified: 2026-08-26T16:16:33.037
Link: CVE-2026-62545
No data.