Impact
Oracle Hyperion Calculation Manager contains a vulnerability that allows an unauthenticated attacker who can reach the system over HTTP to read a subset of the data exposed by the application. The flaw exists in the security component and does not require any prior authentication or privileged access. Successful exploitation results in the disclosure of confidential information but does not affect integrity or availability. This is a CWE-284 insufficient access control flaw. The weakness is reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, where the confidentiality impact is marked as low.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the only officially affected build. No other releases or variants are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. The EPSS score of < 1% suggests a very low but nonzero probability of exploitation. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog, so no documented exploits are known. However, the attack vector is straightforward: an attacker who can reach the HTTP interface can send crafted requests and obtain data without authentication. Inferred from the description, the proper mitigation involves applying the vendor patch or otherwise blocking unauthenticated HTTP access.
OpenCVE Enrichment