Impact
The vulnerability allows an attacker who is only lightly privileged and has network access through HTTP to take over the Oracle Hyperion Calculation Manager. The impact is complete loss of confidentiality, integrity, and availability for that instance, and, because the exploit can change the attack scope, it may also affect other products that interact with the calculation manager.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected.
Risk and Exploitability
The CVSS score of 9.9 places this flaw in the high‑to‑critical range. An attacker would need only low privileged network access via HTTP and requires no user interaction to exploit it. The EPSS score of <1% indicates that real‑world exploitation is currently very low but still possible. The vulnerability is not listed in the CISA KEV catalog, but the vector shows that the attacker can change scope and possibly compromise additional related products after initial takeover.
OpenCVE Enrichment