Impact
An attacker with low privileges who can reach the Oracle Hyperion Calculation Manager over HTTP can tamper with, delete, or insert data and read restricted information. The vulnerability originates in the Security component and allows unauthorized updates, inserts, deletes, and partial reads. The CVSS 3.1 base score of 5.4 reflects moderate confidentiality and integrity impacts. The attack vector is at the network level, short attack complexity, and requires low privileges with no user interaction.
Affected Systems
Oracle Hyperion Calculation Manager, version 11.2.25.0.000.
Risk and Exploitability
The exploit is considered easily exploitable over a network, but the EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, indicating limited current exploitation activity. The CVSS score indicates moderate risk, and the lack of user interaction makes it a realistic threat for attackers who can communicate with the affected instance.
OpenCVE Enrichment