Impact
The flaw in Oracle Hyperion Calculation Manager allows an unauthenticated attacker with physical access to the communication ports of the server to compromise the application. The attacker can create, delete, or modify critical data and gain full read access to all data stored by Hyperion, leading to significant confidentiality and integrity damage. The vulnerability stems from a security component misconfiguration that fails to enforce proper access control.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is vulnerable. The issue resides in the security component of this product.
Risk and Exploitability
Risk and Exploitability: The vulnerability has a CVSS 3.1 base score of 8.0 with AV:A, AC:H, PR:N, UI:N, and S:C. Exploitation requires physical access to the server’s network interface, but no user interaction is necessary. The EPSS score is 0.00215, indicating a very low but non-zero likelihood of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog, indicating that no widespread exploitation has been reported. However, the scope change suggests an attacker could pivot to other components, so the overall risk remains high.
OpenCVE Enrichment