Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Security component of Oracle Hyperion Calculation Manager 11.2.25.0.000 and allows an unauthenticated attacker who can physically reach the hardware executing the application to read a subset of data that should remain confidential. It represents a CWE-284 improper‑access‑control weakness, because the application permits read access without enforcing proper access controls. With a CVSS base score of 3.1, the flaw indicates a low severity but still allows sensitive data exposure.

Affected Systems

The affected system is Oracle Hyperion Calculation Manager version 11.2.25.0.000, provided by Oracle Corporation. No other products or vendors are listed as impacted.

Risk and Exploitability

The CVSS score of 3.1 signals a low‑risk vulnerability that chiefly threatens confidentiality. Exfiltration requires local physical access to the server, making remote exploitation unlikely. EPSS data indicates a very low exploitation probability, and the vulnerability does not appear in the CISA KEV catalog, suggesting no publicly known exploits. Nonetheless, organizations that have not restricted physical access to their servers may face the possibility of unauthorized data read if an adversary gains proximity to the hardware.

Generated by OpenCVE AI on August 25, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce strict physical security controls to limit on‑site access to servers running Oracle Hyperion Calculation Manager.
  • Review and adjust data exposure settings within the application so that only necessary data subsets are accessible, reducing the impact of any potential data read.
  • Monitor application and system logs for anomalous read activity and apply network segmentation to isolate the application from other critical systems.
  • Verify that the application's access control mechanisms enforce a principle of least privilege so that data read permissions are correctly applied, addressing the CWE‑284 weakness.

Generated by OpenCVE AI on August 25, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Physical Access Required for Unauthorized Data Disclosure in Oracle Hyperion Calculation Manager

Tue, 25 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local Data Disclosure via Physical Access in Oracle Hyperion Calculation Manager
Weaknesses CWE-200

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Data Disclosure via Physical Access in Oracle Hyperion Calculation Manager
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:16:50.167Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62604

cve-icon Vulnrichment

Updated: 2026-08-25T14:19:25.916Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:12.797

Modified: 2026-08-25T16:16:57.173

Link: CVE-2026-62604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses