Impact
The vulnerability resides in the Oracle Hyperion Calculation Manager Security component and permits a local attacker who already has high‑privileged access to the host to compromise the application. Successful exploitation gives the attacker unauthorized access to crucial data, allowing reads with high confidentiality impact and updates, inserts, or deletions with lower integrity impact. The CVSS vector indicates a scope change, suggesting that if the initial compromise occurs, other Oracle Hyperion components could also be affected, amplifying the damage potential.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. The scope‑changing nature of the CVSS vector suggests that other Oracle Hyperion related components could also be impacted if the initial compromise spreads.
Risk and Exploitability
The CVSS 3.1 base score of 6.7 indicates moderate severity. Although the EPSS score is less than 1%, the vulnerability is described as easily exploitable by an attacker with high‑privileged local access. Because the issue is not listed in CISA's KEV catalog, the primary risk assessment relies on the local attack vector and the potential for extensive data manipulation. Monitoring for unauthorized privileged activity remains the most effective countermeasure.
OpenCVE Enrichment