Impact
A low‑privileged attacker who can reach the physical communication segment that the Oracle Hyperion Calculation Manager runs on can exploit a vulnerability in the security component of the product. This flaw permits the attacker to perform unauthorized updates, inserts, or deletes on the manager’s accessible data, thereby compromising the integrity of that data. The weakness appears to be an improper access control issue (inferred), as the system allows privileged operations without enforcing proper authorization checks.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 Base Score of 2.6 reflects a low severity with limited impact on confidentiality and availability; the impact is limited to integrity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a modest likelihood of exploitation as of the current data. The attack vector is local (AV:A) and requires the attacker to be on the same physical communication segment, which mitigates the risk relative to remote exploitation. Nonetheless the flaw allows malicious modification of critical business data if the attacker succeeds.
OpenCVE Enrichment