Impact
The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful exploitation requires interaction from a person other than the attacker, yet results in the attacker being able to create, delete, or modify critical data or gain complete access to all accessible data. The impact is a high confidentiality and integrity compromise, with a CVSS 3.1 Base Score of 8.1.
Affected Systems
Oracle Hyperion Calculation Manager, version 11.2.25.0.000, in use by Oracle Corporation.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based via HTTP, requiring a user to interact with the system that initiates the attack. Because the exploitation is unauthenticated, the barrier for entry is low, but the need for a separate human to trigger the attack raises the required complexity. However, once the attacker obtains unauthorized modify or view permissions, the potential for data loss, corruption, or disclosure is substantial.
OpenCVE Enrichment