Impact
A logic flaw in the security component of Oracle Hyperion Calculation Manager allows a low‑privileged attacker with network access via HTTP to compromise the application. Successful exploitation enables the attacker to read critical data and, in some scenarios, to add, modify, or delete information, effectively gaining unauthorized access and control over the data stored in the system. The weakness is an access control flaw, impacting confidentiality and integrity.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. No other versions or products are listed as vulnerable, but the impact may extend to other connected Hyperion components depending on configuration.
Risk and Exploitability
The CVSS v3.1 score of 7.6 indicates a high severity with substantial confidentiality and integrity impacts. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires network access to the HTTP interface and user interaction from a non‑attacker, indicating that while exploitation is less likely in a tightly controlled environment, an attacker could still succeed if the service is exposed to external users or if social engineering succeeds.
OpenCVE Enrichment