{"cve":"CVE-2026-62564","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"11.2.25.0.000"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Hyperion Infrastructure Technology","source":"cna","vendor":"Oracle Corporation"},"product":"hyperion_infrastructure_technology","vendor":"oracle"}],"created":"2026-08-19T01:15:12.516278+00:00","title":"Low-privilege Local Access Control Vulnerability in Oracle Hyperion Infrastructure","updated":"2026-08-25T22:00:13.456894+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":["CWE-284"]},"epss":{"score":0.00154},"mitre":{"cpes":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:00:30.695000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.5,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/62xxx/CVE-2026-62564.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-25T18:03:32.919000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:08.253000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.5,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-62564.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-25T18:17:57.813000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"weaknesses":["CWE-284","NVD-CWE-noinfo"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":5.5,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"a1568e55-823b-4927-9c80-3db4d7e1f167"},{"created":"2026-08-19T01:30:00+00:00","data":[{"details":{"new":"Data access via low‑privilege installation and configuration flaw in Oracle Hyperion Infrastructure Technology","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"10018c02-d59d-4e95-8419-12a9cc5c6d9a"},{"created":"2026-08-21T10:00:00+00:00","data":[{"details":{"new":null,"old":"Data access via low‑privilege installation and configuration flaw in Oracle Hyperion Infrastructure Technology"},"type":"title"},{"details":{"added":[],"removed":["CWE-284"]},"type":"weaknesses"}],"id":"518c5aab-95d2-4064-938b-c1bfe6f41f3d"},{"created":"2026-08-21T12:45:00+00:00","data":[{"details":{"new":"Improper Access Control Leading to Unauthorized Data Access in Oracle Hyperion Infrastructure Technology","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"c5114e82-0e69-442b-9cd1-2098f9671e0a"},{"created":"2026-08-25T16:30:00+00:00","data":[{"details":{"added":["NVD-CWE-noinfo"],"removed":[]},"type":"weaknesses"}],"id":"040fd58b-3239-440e-a345-c285a1bfcb1c"},{"created":"2026-08-25T18:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"58e952b7-393e-4a35-b2f8-3ad63559ebdb"},{"created":"2026-08-25T19:00:00+00:00","data":[{"details":{"new":null,"old":"Improper Access Control Leading to Unauthorized Data Access in Oracle Hyperion Infrastructure Technology"},"type":"title"}],"id":"b6a4add6-0817-440c-aeed-26cd5caba5cd"},{"created":"2026-08-25T22:15:00+00:00","data":[{"details":{"new":"Low-privilege Local Access Control Vulnerability in Oracle Hyperion Infrastructure","old":null},"type":"title"}],"id":"cec8115b-aaf2-4a17-82cb-2ec7c00765a5"}],"cpes":{"data":["cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:00:30.695000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":5.5,"vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00154},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Low-privilege Local Access Control Vulnerability in Oracle Hyperion Infrastructure","provider":"enrichment"},"updated":{"data":"2026-08-25T22:00:13.456894+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$hyperion_infrastructure_technology"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284","NVD-CWE-noinfo"],"providers":["nvd","vulnrichment","enrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:00:30.695000+00:00","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-25T17:56:36.587000+00:00","vendors":[],"vulnrichment_repo_path":"2026/62xxx/CVE-2026-62564.json","weaknesses":["CWE-284"]}}