Impact
The vulnerability in Oracle Hyperion Calculation Manager allows an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, read restricted subsets of data, and partially deny service. This results in integrity and availability impacts, as reflected by a CVSS v3.1 score of 7.0 with low confidentiality impact but high integrity and low availability impact, indicating a medium to high severity risk.
Affected Systems
Oracle Corporation’s Hyperion Calculation Manager, version 11.2.25.0.000, is affected by the flaw.
Risk and Exploitability
Exploitation requires only network connectivity to the HTTP endpoint of the Hyperion server and no credentials. The flaw is difficult to exploit remotely, making it a less practical threat for attackers with internet or internal network access; the EPSS score of less than 1% indicates a very low probability of exploitation. Nevertheless, the medium‑high CVSS base score, lack of authentication requirement, and absence of a KEV listing highlight a notable risk for organizations running this product.
OpenCVE Enrichment