Impact
This vulnerability allows an attacker who already has high privileged access on the system hosting Oracle Hyperion Calculation Manager to compromise that application. An attacker can then create, delete, or modify critical data stored by Hyperion, thereby jeopardizing data integrity. The weakness is a failure of proper access control within the application’s security component, which is reflected in the CVSS vector with a high integrity impact and no impact on confidentiality or availability.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. No other products or versions were listed.
Risk and Exploitability
The CVSS 3.1 base score of 4.1 indicates a low severity, primarily affecting integrity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is unlikely at present. However, because the attack requires a local high‑privileged login, organizations that provide privileged access to the Hyperion environment must ensure that such accounts are tightly controlled and monitored. If an attacker gains that foothold, they can alter critical data without affecting application availability or confidentiality.
OpenCVE Enrichment