Impact
A vulnerability in the security component of Oracle Hyperion Calculation Manager (version 11.2.25.0.000) allows an unauthenticated attacker who can reach the system over HTTP to read a limited subset of data that is normally protected by the application. The flaw does not affect integrity or availability and is classified as a confidentiality‑only weakness.
Affected Systems
The affected product is Oracle Hyperion Calculation Manager from Oracle Corporation. The specific affected version is 11.2.25.0.000; no other releases are listed in the available vendor information.
Risk and Exploitability
The CVSS base score of 3.7 reflects a low‑to‑moderate severity and indicates that only confidentiality is impacted. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog, suggesting that current exploit activity is unknown. The likely attack vector is an unauthenticated HTTP connection to the Hyperion web interface; the attacker merely needs network access and does not require any credentials or privileged configuration. Successful exploitation would reveal a subset of data, but no privilege escalation or denial of service is possible.
OpenCVE Enrichment