Impact
Oracle Hyperion Calculation Manager is vulnerable to a flaw that empowers a low‑privilege attacker with SFTP network access to create, delete, or modify critical data and to gain unauthorized access to all Hyperion data. The vulnerability permits the compromise of confidentiality and integrity of the system’s information, and it has the potential to affect other Oracle Hyperion products that share data through a scope change.
Affected Systems
The affected product is Oracle Hyperion Calculation Manager version 11.2.25.0.000 from Oracle Corporation. While the primary impact is on this version, the description notes that successful exploitation may also affect other Oracle Hyperion products that share data structures.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 signals a high‑severity vulnerability. The EPSS score is below 1 %, indicating a low but non‑zero likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The attack vector is network‑based via SFTP, and only low‑privileged accounts are required, making it a considerable threat to data integrity and confidentiality in environments that allow low‑privileged SFTP access.
OpenCVE Enrichment