Impact
A vulnerability in Oracle Hyperion Calculation Manager allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw permits full takeover of the system, leading to disclosure, modification, and disruption of data and services, as reflected by a CVSS v3.1 base score of 8.1 for confidentiality, integrity, and availability impact.
Affected Systems
The affected product is Oracle Hyperion Calculation Manager version 11.2.25.0.000 from Oracle Corporation. No other versions or products are listed as impacted.
Risk and Exploitability
The attack vector is inferred to be remote network access over HTTP, requiring no authentication. The CVSS 8.1 score indicates a high severity. The EPSS score of 0.00315 (less than 1%) indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV, so the immediate exploitation likelihood is uncertain but the impact is severe.
OpenCVE Enrichment