Impact
The vulnerability is in the Security component of Oracle Hyperion Calculation Manager and is identified as a CWE‑284 (Broken Access Control) weakness. It permits an attacker with low privileges who can reach the application over HTTP to take control of the server, compromising confidentiality, integrity, and availability. The flaw has a CVSS v3.1 score of 8.8, indicating a high‑impact weakness that allows the attacker to achieve a full takeover.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the only version identified as affected. The issue applies to all installations of this product on supported platforms.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high‑impact vulnerability that requires only low complexity and low privileges. It can be exploited over the public network using HTTP without user interaction. The EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalogue. A low‑privileged attacker can compromise the system by sending a crafted HTTP request to the vulnerable service.
OpenCVE Enrichment