Impact
This vulnerability enables an attacker with low privileges who can access the web interface of Oracle Hyperion Calculation Manager to perform unauthorized insert, update or delete operations on data. It requires human interaction from a user other than the attacker, yet the exploitation path is straightforward via an HTTP request. The impact is limited to the integrity of stored data, as disclosed by the CVSS 3.1 vector scoring only integrity (I:L).
Affected Systems
The affected system is Oracle Hyperion Calculation Manager version 11.2.25.0.000, as identified by the vendor/product name and CPE string provided. No other versions or vendors are listed.
Risk and Exploitability
With a CVSS base score of 3.5, this vulnerability is considered low severity. The CVE notes that it can be exploited remotely over HTTP by a low‑privileged attacker, but successful attacks also require human interaction from a user other than the attacker, limiting its immediate impact. EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating that wide‑scale exploitation has not been observed. Nevertheless, any low‑privileged user able to access the Hyperion web interface could perform unauthorized data modification, so appropriate controls should be applied.
OpenCVE Enrichment