Impact
The vulnerability in Oracle Hyperion Calculation Manager allows an unauthenticated attacker with network access to the HTTP interface to compromise the application. The attack requires user interaction, such as a legitimate user visiting a malicious URL, but does not need special credentials or elevated privileges. Successful exploitation can lead to unauthorized reading of critical data or modification (update, insert, delete) of data, causing loss of confidentiality and partial loss of integrity.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000, provided by Oracle Corporation, is the sole affected build. The product is used for enterprise planning and calculation processes.
Risk and Exploitability
The CVSS v3.1 base score of 5.9 indicates a moderate risk. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is a network-based HTTP request that relies on a victim user visiting a crafted URL; no privileged access is required. Although exploitation is less likely, the potential for data leakage or manipulation remains significant, especially in environments where the Hyperion interface is exposed to broader networks.
OpenCVE Enrichment