Impact
Oracle Hyperion Calculation Manager version 11.2.25.0.000 contains a flaw in its Security component that allows an unauthenticated attacker, who can log on to the underlying infrastructure, to compromise the application. This flaw, identified as a CWE-284 Permission or Access Control weakness, enables the attacker to read a subset of data exposed by the application, with no mention of privilege escalation, code execution, or availability impact.
Affected Systems
Affected systems are Oracle Hyperion Calculation Manager 11.2.25.0.000, distributed by Oracle Corporation. The vulnerability applies only to the specified version and component; no other versions or products are listed.
Risk and Exploitability
The CVSS 3.1 base score of 4.0 indicates a low severity threat with a confidentiality impact. EPSS indicates an exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation evidence. The likely attack vector is local, requiring the attacker to have infrastructure logon access; no public exploit code is documented. Overall risk is moderate but low, primarily affecting data confidentiality within the affected installation.
OpenCVE Enrichment