Impact
This vulnerability is a flaw in the Web Client–Unicode component of Oracle Hyperion Data Relationship Management that allows unauthenticated HTTP requests to gain unauthorized access to data (CWE-284). Successful exploitation results in unrestricted read access to all data the service exposes and can also disrupt service availability, causing a partial denial of service.
Affected Systems
Oracle Hyperion Data Relationship Management, version 11.2.23.0.000, is the only product currently reported as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates a high confidentiality impact and a moderate availability impact. The EPSS score of 0.0032 (approximately <1%) indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based through unauthenticated HTTP requests, and the exploit is considered easily exploitable with simple HTTP requests, making it highly dangerous in environments where the Hyperion Web Client is exposed to the network.
OpenCVE Enrichment