Impact
The vulnerability in Oracle Hyperion Calculation Manager version 11.2.25.0.000 allows an attacker with low privileges who can reach the HTTP interface to read a limited set of data. The flaw is network-based and results in a confidentiality compromise without impacting integrity or availability. While the vulnerability confines itself to a subset of accessible data, the scope change noted by Oracle indicates that additional Oracle products or components may be affected upon successful exploitation.
Affected Systems
The impacted product is Oracle Hyperion Calculation Manager version 11.2.25.0.000. The advisory notes that a scope change could mean attacks may affect other Oracle products or components, but no other specific versions or vendors are indicated by the CNA. No explicit list from the advisory beyond the single product exists.
Risk and Exploitability
The attack vector is network-based HTTP access, requiring only low or remote privileges. Because the EPSS score is less than 1 percent, the likelihood of exploitation is low, but the CVSS base score of 5.0 indicates a moderate risk driven solely by a low severity confidentiality impact. The vulnerability is not listed in CISA's KEV catalog, so no known active exploit campaigns are recorded. However, the scope change suggests an attacker could potentially reach additional data sources, so administrators should treat the issue as a potential data disclosure path.
OpenCVE Enrichment