CVE-2026-62606: Low severity Oracle Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access to Oracle Hyperion Calculation Manager and network access to the affected service over HTTP. No user interaction is required, but exploitation is rated difficult.
What is the impact of a successful attack?
A successful attack can provide unauthorized read access to a subset of data accessible through Oracle Hyperion Calculation Manager. The vulnerability has confidentiality impact only; no integrity or availability impact is stated.
Which version is identified as affected?
The affected supported version identified is 11.2.25.0.000.