Impact
The vulnerability in Oracle Hyperion Calculation Manager, version 11.2.25.0.000, permits an unauthenticated attacker with network access via HTTP to compromise the system. Compromise is difficult to exploit but can lead to unauthorized access to critical data or complete access to all data that the application manages. The weakness results in a confidentiality impact with a CVSS 3.1 Base Score of 5.3.
Affected Systems
Oracle Hyperion Calculation Manager 11.2.25.0.000 is the only version listed as affected. This product is part of the Oracle Hyperion product suite.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, meaning no publicly known exploit. The likely attack vector is over the network via HTTP, with no authentication required but human interaction needed for successful exploitation. If exploited, the attacker would gain unauthorized read access to sensitive data.
OpenCVE Enrichment