Impact
Oracle Hyperion Calculation Manager has a vulnerability in its security component that enables an unauthenticated attacker with access to the physical communication segment attached to the server hardware to compromise the application. The flaw allows such an attacker to perform unauthorized update, insert or delete operations on data that is normally protected, as well as read a subset of that data. The impact affects confidentiality and integrity but not availability, and the vulnerability is exploitable without any authentication. The threat applies only to environments where the attacker can reach the physical network segment; there is no remote internet-facing exploitation vector, and no credentials are required from the user side.
Affected Systems
Oracle Corporation's Hyperion Calculation Manager, version 11.2.25.0.000, is affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates a medium severity with low confidentiality and integrity impact. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is physical local network adjacency (AV:A), meaning the risk is confined to those with physical access to the hardware or the adjacent network segment. If physical security controls are loose, the risk could be higher for internal threat actors with network access, but for a typical organization with tight physical and network containment, the overall risk remains moderate.
OpenCVE Enrichment