Impact
A flaw in Oracle Hyperion Calculation Manager’s security component allows an unauthenticated attacker who can reach the system over HTTP to perform unauthorized update, insert, or delete operations on data accessible through the application. This grants direct compromise of data integrity in the affected instance. The issue represents improper access control, allowing data modifications without proper authentication.
Affected Systems
Oracle Corporation’s Oracle Hyperion Calculation Manager, version 11.2.25.0.000.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 indicates moderate severity, with integrity impacts only. EPSS shows a very low exploitation probability of <1%, and the vulnerability is not listed in the CISA KEV catalog. The flaw is an instance of improper access control that can be exploited remotely over unauthenticated HTTP; no special configuration beyond network reach to the exposed endpoints is required.
OpenCVE Enrichment