Impact
An unauthenticated attacker who can reach Oracle Hyperion Calculation Manager over the network via HTTP can read a subset of the system’s data. The flaw is an information‑disclosure vulnerability that affects confidentiality only, with no impact on integrity or availability. The CVSS score of 3.7 reflects a low exploitation probability but still signals that sensitive application data may be exposed.
Affected Systems
Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected. No other products or versions were identified in the current advisory.
Risk and Exploitability
The attack requires only network access to the exposed HTTP interface and no authentication. With an EPSS score of less than 1% and the vulnerability not listed in CISA’s KEV catalog, the likelihood of exploitation is very low. Nonetheless, the potential impact remains confidential data exposure, which could compromise sensitive reporting or financial information.
OpenCVE Enrichment