Impact
A low‑privileged attacker with network access to Oracle Hyperion Calculation Manager can exploit an easily exploitable security flaw that allows unauthorized access to critical data. The flaw is not a denial‑of‑service but an escape of confidentiality boundaries, as the CVSS vector shows a scope change (S:C) and a high confidentiality impact (C:H). The attacker can acquire complete data visibility within the system without needing higher privileges or user interaction.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. The vulnerability targets the Security component of this product, and the description notes that attacks may impact additional Oracle Hyperion products beyond Calculation Manager.
Risk and Exploitability
The CVSS Base Score of 7.7 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and it is not listed in CISA’s KEV catalog, suggesting no confirmed exploits at this time. The attack vector is inferred to be network‑based HTTP access, with no user interaction required. Given the scope change, a low‑privileged user could elevate their impact, making the risk significant for organizations that expose the calculation manager over the network.
OpenCVE Enrichment