CVE-2026-70711: Low severity Oracle Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to Oracle Hyperion Calculation Manager version 11.2.25.0.000 where an unauthenticated attacker can log on to the infrastructure hosting the product. The attack is local and requires interaction from someone other than the attacker.
What access and conditions does an attacker need?
The attacker needs access to log on to the infrastructure where Oracle Hyperion Calculation Manager runs. Exploitation is difficult, requires local attack conditions, and depends on human interaction.
What could a successful attack allow?
A successful attack can provide unauthorized read access to a subset of data accessible to Oracle Hyperion Calculation Manager. It can also allow unauthorized update, insert, or delete operations on some accessible data.
How can I determine whether my environment is affected?
Verify whether Oracle Hyperion Calculation Manager is deployed at version 11.2.25.0.000. Also assess whether unauthenticated users can log on to the infrastructure hosting the application and whether a user could be induced to perform the required interaction.