CVE-2026-62604: Low severity Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to environments where an attacker can access the physical communication segment connected to the hardware running Oracle Hyperion Calculation Manager. The affected supported version identified is 11.2.25.0.000.
Does an attacker need credentials or user interaction to exploit it?
No credentials or user interaction are required. However, exploitation is described as difficult and requires physical-network-segment access.
What is the expected impact of successful exploitation?
A successful attack can provide unauthorized read access to a subset of data accessible to Oracle Hyperion Calculation Manager. The stated impact is limited to confidentiality; integrity and availability are not affected.