Impact
The vulnerability resides in the security component of Oracle Hyperion Calculation Manager and allows a high‑privileged attacker with network access via HTTP to compromise the system. Exploitation can result in unauthorized reading of critical data, arbitrary updates or deletions of data, and the ability to cause a partial denial of service. The CVSS v3.1 base score is 7.2, with high confidentiality impact, integrity and availability impacts. Attackers must possess high privileges but can initiate the attack remotely over the network.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. The issue is specifically tied to this product; however, because the scope is changed, other Oracle Hyperion products that interact with the Calculation Manager could also be compromised indirectly.
Risk and Exploitability
The CVSS score indicates a moderate‑to‑high risk. With the EPSS score reported as < 1%, the likelihood of exploitation in the wild is considered very low but not zero, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker must have high‑privilege credentials and network connectivity to the Hyperion service via HTTP. Given the high privilege requirement, an internal attacker or a compromised account could exploit the flaw to gain broad access to Confidential data, alter data, and disrupt service availability. The scope change suggests potential collateral impact on other bundled Oracle Hyperion components. Addressing this requires timely patching and network hardening.
OpenCVE Enrichment