Oracle Hyperion Calculation Manager: data exposure via Security
Low3.7CVE-2026-70682 · Published Aug 18, 2026 · updated Aug 25, 2026
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle Hyperion Calculation Manager Product | <= 11.2.25.0.000 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | Helidon: data tampering via Imperative Web Server | High8.6 | No fix yet |
| Aug 18 | Helidon: data tampering via Imperative Web Server | Critical9.9 | No fix yet |
| Aug 18 | Helidon: data tampering via Imperative Web Server | High8.3 | No fix yet |
| Aug 18 | Helidon: flaw in Imperative Web Server | Medium5.3 | No fix yet |
| Aug 18 | Helidon: data tampering via Imperative Web Server | High7.3 | No fix yet |
| Aug 18 | Helidon: denial of service via Imperative Web Server | High7.5 | No fix yet |