Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-08-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access via HTTP can trigger actions in Oracle Hyperion Calculation Manager 11.2.25.0.000 that ultimately allow an unauthenticated user to perform unauthorized update, insert, or delete operations on data that is normally protected. The vulnerability requires a human interaction from a person other than the attacker, which means the attacker relies on social engineering or exploitation of cursory user awareness to achieve the final data modification. This flaw directly compromises the integrity of the application data but does not grant direct remote code execution or full system compromise. The weakness is rooted in improper access control checks within the security component of the product.

Affected Systems

Oracle Hyperion Calculation Manager version 11.2.25.0.000, a product of Oracle Corporation.

Risk and Exploitability

The vulnerability is scored with a CVSS 3.1 Base Score of 4.3, indicating moderate severity with a focus on integrity impact. The EPSS Score is 0.00263, indicating a very low but nonzero exploitation probability, and it is not listed in the CISA KEV catalog, suggesting it is not widely exploited. Exploitation requires HTTP access to the application and relies on a second human user, implying that the likelihood of successful attacks depends on the organization’s exposure to untrusted networks and user safeguarding practices. The attack vector is likely an unauthenticated web session that circumvents normal authorization controls.

Generated by OpenCVE AI on August 25, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply any available patch or upgrade from Oracle for Hyperion Calculation Manager 11.2.25.0.000
  • Restrict HTTP access to the application by implementing firewall rules, VPN access, or network segmentation so that only trusted networks can reach the service
  • Enable detailed audit logging for data modification operations and configure alerts for unauthorized insert, update, or delete actions
  • Conduct security awareness training for users to recognize social engineering attempts that could facilitate the required human interaction

Generated by OpenCVE AI on August 25, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle Hyperion Calculation Manager

Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle Hyperion Calculation Manager
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:22:43.141Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70683

cve-icon Vulnrichment

Updated: 2026-08-25T16:20:16.174Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:20.193

Modified: 2026-08-25T17:18:13.997

Link: CVE-2026-70683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T18:00:15Z

Weaknesses