Impact
An unauthenticated attacker with network access via HTTP can trigger actions in Oracle Hyperion Calculation Manager 11.2.25.0.000 that ultimately allow an unauthenticated user to perform unauthorized update, insert, or delete operations on data that is normally protected. The vulnerability requires a human interaction from a person other than the attacker, which means the attacker relies on social engineering or exploitation of cursory user awareness to achieve the final data modification. This flaw directly compromises the integrity of the application data but does not grant direct remote code execution or full system compromise. The weakness is rooted in improper access control checks within the security component of the product.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000, a product of Oracle Corporation.
Risk and Exploitability
The vulnerability is scored with a CVSS 3.1 Base Score of 4.3, indicating moderate severity with a focus on integrity impact. The EPSS Score is 0.00263, indicating a very low but nonzero exploitation probability, and it is not listed in the CISA KEV catalog, suggesting it is not widely exploited. Exploitation requires HTTP access to the application and relies on a second human user, implying that the likelihood of successful attacks depends on the organization’s exposure to untrusted networks and user safeguarding practices. The attack vector is likely an unauthenticated web session that circumvents normal authorization controls.
OpenCVE Enrichment