CVE-2026-70682: Low severity Oracle Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with network access to the Oracle Hyperion Calculation Manager HTTP service could attempt exploitation. The attack complexity is high, so exploitation is described as difficult.
What is the impact of a successful attack?
Successful exploitation can provide unauthorized read access to a subset of data accessible through Oracle Hyperion Calculation Manager. The stated impact is limited to confidentiality; integrity and availability are not affected.
Which version is identified as affected?
The affected supported version identified is Oracle Hyperion Calculation Manager 11.2.25.0.000.