Impact
The vulnerability in Oracle Hyperion Calculation Manager arises from an access-control weakness involving insufficient checks on user privileges and missing authentication for critical functions (CWE-306). This flaw allows an unauthenticated attacker who has logged on to the affected infrastructure to bypass authorization and perform unauthorized updates, inserts or deletes on data accessible within the application, as well as read a subset of that data. The impact is limited to moderate confidentiality and integrity loss with a CVSS 3.1 base score of 3.6.
Affected Systems
Affected systems include Oracle Hyperion Calculation Manager version 11.2.25.0.000. No other versions are known to be affected by this vulnerability.
Risk and Exploitability
The CVSS score of 3.6 indicates low severity, and the EPSS score of <1% suggests a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV. Based on the description, the likely attack vector is local or physical access to the infrastructure, inferred from the requirement that the attacker must already have logon access and that human interaction from a person other than the attacker is needed. The attack vector is therefore limited to local or physical compromise rather than remote exploitation.
OpenCVE Enrichment