Impact
This occurs in the Security component of Oracle Hyperion Calculation Manager and permits an unauthenticated attacker who can reach the target over HTTP to potentially read a subset of data exposed by the application. The flaw requires no authentication but does demand a human interaction from someone other than the attacker, limiting the attack surface to scenarios where a user accepts a malicious generic request. The impact is confined to low confidentiality damage, as the attacker cannot modify or delete data, and no integrity or availability effects are described.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the only affected release. No other versions or build numbers are listed, so the risk is isolated to this specific build.
Risk and Exploitability
The CVSS v3.1 base score of 3.1 reflects a low severity, with no privileges required and a user interface step needed. The EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV, indicating a low likelihood of widespread exploitation. An attacker must have network access to the HTTP interface and rely on a victim’s interaction to trigger the read, which further reduces the risk of automated, large‑scale attacks.
OpenCVE Enrichment