Impact
The flaw exists in the Security component of Oracle Hyperion Calculation Manager and allows a local access‑control bypass that grants an attacker who can log onto the host running the application unauthorized read, update, insert or delete operations on the data managed by the instance. The impact includes a high confidentiality loss and moderate integrity harm, as reflected in the CVSS vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N. This is an improper access control weakness.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the affected product, and the scope change may also affect other Oracle products that depend on the same underlying components. Organizations running this version should verify that no other applications share the same vulnerable component.
Risk and Exploitability
The vulnerability requires that the attacker already has host privileges, indicating a local attack vector. The EPSS score of < 1% suggests a very low current exploitation probability, but the CVSS base score of 7.9 demonstrates a moderate‑to‑high severity. Because the flaw is not listed in the CISA KEV catalog, current exploitation activity is uncertain, yet the potential for unauthorized data access or modification warrants a serious risk posture for any environment running the affected version.
OpenCVE Enrichment