Impact
The vulnerability allows low‑privileged attackers who can reach the Oracle Hyperion Calculation Manager over HTTP to gain unauthorized access to critical data and, in some cases, cause a partial denial of service. The weakness is rooted in improper access control, as evidenced by its CVSS vector and the impact on confidentiality and availability, corresponding to weakness CWE‑284.
Affected Systems
Oracle Corporation’s Hyperion Calculation Manager 11.2.25.0.000 is affected. The flaw resides in the Security component of that product version and is present only in the supported 11.2.25.0.000 release.
Risk and Exploitability
With a CVSS 3.1 base score of 7.1, the vulnerability presents a moderate‑to‑high risk, particularly given its confidentiality (H) and availability (L) impact. The EPSS score of 0.00348 indicates a very low, yet non‑zero, probability of exploitation; however, the lack of measurable exploitation data does not diminish the potential for an attacker with network access via HTTP and low privileges to exploit this flaw. The risk is compounded by the fact that the flaw is not already listed in CISA’s KEV catalog, indicating that exploitation may yet be observed in the wild.
OpenCVE Enrichment