Impact
A flaw in the security component of Oracle Hyperion Calculation Manager allows an unauthenticated attacker with network access through HTTP to compromise the application, resulting in full control over Confidentiality, Integrity, and Availability of the system.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected; the product is part of the Oracle Hyperion product family and runs on the specified version.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity. The EPSS score of < 1% indicates a low yet non-zero likelihood of exploitation, and the lack of a KEV listing does not mitigate the high impact and the described attack path - requiring only HTTP access without authentication - suggests a realistic exploitation likelihood if the vulnerability remains unpatched.
OpenCVE Enrichment