6.5mediumMedium

CVE-2026-62578

Oracle Hyperion Calculation Manager

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable only from the same local or logical network.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-284
Assigned by
secalert_us@oracle.com

Dates

Published
2026-08-18
Last modified
2026-08-26
Sources
NVD

Affected products

  • Oracle Hyperion Calculation Manager11.2.25.0.000

As listed in the NVD configuration data. Not a statement about your estate.

References