Impact
The vulnerability in Oracle Hyperion Calculation Manager permits a low‑privileged attacker with HTTP network access to create, delete, or modify critical data. This capability compromises confidentiality and integrity of all data accessible by the application. No explicit description of the underlying weakness is provided in the advisory, but the effect indicates a flaw that allows unauthorized data manipulation.
Affected Systems
Oracle Hyperion Calculation Manager, version 11.2.25.0.000, the only version reported as affected.
Risk and Exploitability
The CVSS v3.1 base score of 9.6 demonstrates a high severity. The EPSS score reflects less than 1% exploitation probability, indicating a low yet non-zero chance of real-world exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks would be network‑based via HTTP and require only low privileges, and the identified scope change suggests exploitation could impact additional products in the environment.
OpenCVE Enrichment