Impact
This vulnerability exists in the Security component of Oracle Hyperion Calculation Manager 11.2.25.0.000 and allows an unauthenticated attacker who can physically reach the hardware executing the application to read a subset of data that should remain confidential. It represents a CWE-284 improper‑access‑control weakness, because the application permits read access without enforcing proper access controls. With a CVSS base score of 3.1, the flaw indicates a low severity but still allows sensitive data exposure.
Affected Systems
The affected system is Oracle Hyperion Calculation Manager version 11.2.25.0.000, provided by Oracle Corporation. No other products or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 3.1 signals a low‑risk vulnerability that chiefly threatens confidentiality. Exfiltration requires local physical access to the server, making remote exploitation unlikely. EPSS data indicates a very low exploitation probability, and the vulnerability does not appear in the CISA KEV catalog, suggesting no publicly known exploits. Nonetheless, organizations that have not restricted physical access to their servers may face the possibility of unauthorized data read if an adversary gains proximity to the hardware.
OpenCVE Enrichment