Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach Oracle Hyperion Calculation Manager over the network via HTTP can read a subset of the system’s data. The flaw is an information‑disclosure vulnerability that affects confidentiality only, with no impact on integrity or availability. The CVSS score of 3.7 reflects a low exploitation probability but still signals that sensitive application data may be exposed.

Affected Systems

Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. No other products or versions were identified in the current advisory.

Risk and Exploitability

The attack requires only network access to the exposed HTTP interface and no authentication. With an EPSS score of less than 1% and the vulnerability not listed in CISA’s KEV catalog, the likelihood of exploitation is very low. Nonetheless, the potential impact remains confidential data exposure, which could compromise sensitive reporting or financial information.

Generated by OpenCVE AI on August 26, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s published patch or update for 11.2.25.0.000 immediately
  • Restrict network access to the Hyperion server by configuring firewalls or VPNs to allow HTTP only from trusted hosts
  • Enable and monitor audit logs for data read operations to detect and investigate any unauthorized attempts

Generated by OpenCVE AI on August 26, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Information Disclosure via HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-284

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Read in Oracle Hyperion Calculation Manager 11.2.25.0.000
Weaknesses CWE-200

Tue, 25 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Read in Oracle Hyperion Calculation Manager 11.2.25.0.000
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:27:18.193Z

Reserved: 2026-07-14T14:54:48.739Z

Link: CVE-2026-62533

cve-icon Vulnrichment

Updated: 2026-08-26T13:45:24.614Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:05.900

Modified: 2026-08-26T16:16:31.810

Link: CVE-2026-62533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T05:30:18Z

Weaknesses