Impact
A flaw in the security component of Oracle Hyperion Calculation Manager 11.2.25.0.000 allows an attacker who can physically connect to the device’s communication segment to bypass authentication controls and read or obtain all data stored in the system. The vulnerability carries a CVSS v3.1 base score of 6.5, indicating a moderate severity level with a high confidentiality impact, while integrity and availability remain unaffected.
Affected Systems
The only impacted product is Oracle Hyperion Calculation Manager 11.2.25.0.000. No other vendors or versions are listed as affected.
Risk and Exploitability
The CVSS score signals moderate risk, and the EPSS score of less than 1 percent suggests that actual exploitation is expected to be rare. Because the attack requires physical proximity to the hardware’s communication interface, the real‑world attack surface is limited to environments where an adversary can access the machine directly. If the attacker succeeds, the primary consequence is unauthorized disclosure of critical data, consistent with the stated confidentiality impact.
OpenCVE Enrichment