CVE-2026-62533: Low severity Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The affected supported version is Oracle Hyperion Calculation Manager 11.2.25.0.000, specifically its Security component.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker can attempt exploitation over the network through HTTP, and no user interaction is required; however, exploitation is rated difficult.
What is the potential impact of a successful attack?
A successful attack can provide unauthorized read access to a subset of data accessible through Oracle Hyperion Calculation Manager. The stated impact is limited to confidentiality; integrity and availability are not affected.