Impact
A flaw in Oracle Hyperion Calculation Manager version 11.2.25.0.000 permits an attacker who is already logged on to the infrastructure where the product runs to compromise the software. The weakness enables unauthorized access to confidential data and, because the impact scope changes, could extend to full control over all data accessible by the product. The vulnerability is an access‑control deficiency that can lead to data disclosure.
Affected Systems
The affected vendor is Oracle Corporation and the impacted product is Oracle Hyperion Calculation Manager. The specific version affected is 11.2.25.0.000. No other products or versions are listed, though the issue may also affect any other products that interact with Hyperion CM.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a high severity for confidentiality impacts. The exploitability vector shows local access with no privilege separation and no user interaction, implying that an attacker who has any local foothold can exploit the flaw. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high CVSS base score and local nature mean that an attacker who gains local access can still compromise the system.
OpenCVE Enrichment