Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This occurs in the Security component of Oracle Hyperion Calculation Manager and permits an unauthenticated attacker who can reach the target over HTTP to potentially read a subset of data exposed by the application. The flaw requires no authentication but does demand a human interaction from someone other than the attacker, limiting the attack surface to scenarios where a user accepts a malicious generic request. The impact is confined to low confidentiality damage, as the attacker cannot modify or delete data, and no integrity or availability effects are described.

Affected Systems

Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the only affected release. No other versions or build numbers are listed, so the risk is isolated to this specific build.

Risk and Exploitability

The CVSS v3.1 base score of 3.1 reflects a low severity, with no privileges required and a user interface step needed. The EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV, indicating a low likelihood of widespread exploitation. An attacker must have network access to the HTTP interface and rely on a victim’s interaction to trigger the read, which further reduces the risk of automated, large‑scale attacks.

Generated by OpenCVE AI on August 26, 2026 at 04:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch or upgrade to a newer, non‑affected release.
  • Restrict external HTTP access to Hyperion by configuring firewalls or requiring VPN connections so that only trusted internal users can reach the application.
  • Implement monitoring for abnormal data read activity and set alerts for potential unauthorized data exposure.

Generated by OpenCVE AI on August 26, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Read Vulnerability in Oracle Hyperion Calculation Manager
Weaknesses CWE-200
CWE-284

Tue, 25 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-200

Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-200

Fri, 21 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-284
CWE-285
CWE-306

Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-284
CWE-285
CWE-306

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:28:39.082Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62461

cve-icon Vulnrichment

Updated: 2026-08-26T13:45:12.086Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:02.690

Modified: 2026-08-26T16:16:30.250

Link: CVE-2026-62461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:45:05Z

Weaknesses