Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Calculation Manager has a vulnerability in its security component that enables an unauthenticated attacker with access to the physical communication segment attached to the server hardware to compromise the application. The flaw allows such an attacker to perform unauthorized update, insert or delete operations on data that is normally protected, as well as read a subset of that data. The impact affects confidentiality and integrity but not availability, and the vulnerability is exploitable without any authentication. The threat applies only to environments where the attacker can reach the physical network segment; there is no remote internet-facing exploitation vector, and no credentials are required from the user side.

Affected Systems

Oracle Corporation's Hyperion Calculation Manager, version 11.2.25.0.000, is affected. No other versions or products are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates a medium severity with low confidentiality and integrity impact. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is physical local network adjacency (AV:A), meaning the risk is confined to those with physical access to the hardware or the adjacent network segment. If physical security controls are loose, the risk could be higher for internal threat actors with network access, but for a typical organization with tight physical and network containment, the overall risk remains moderate.

Generated by OpenCVE AI on August 25, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict physical access to the network segment where Hyperion Calculation Manager runs to authorized personnel only
  • Configure network segmentation and firewall rules to limit traffic to the Hyperion services, permitting only required internal hosts
  • Apply any available Oracle patch for version 11.2.25.0.000 as soon as it is released; before patching, monitor system logs for suspicious data manipulation or read attempts

Generated by OpenCVE AI on August 25, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Physical Network Access in Oracle Hyperion Calculation Manager

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Physical Network Access in Oracle Hyperion Calculation Manager

Tue, 25 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability Allowing Data Modification and Read in Oracle Hyperion Calculation Manager
Weaknesses CWE-1105

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability Allowing Data Modification and Read in Oracle Hyperion Calculation Manager
Weaknesses CWE-1105

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:17:04.489Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62603

cve-icon Vulnrichment

Updated: 2026-08-25T14:19:23.320Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:12.677

Modified: 2026-08-25T16:16:57.057

Link: CVE-2026-62603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses