Impact
This vulnerability resides in the access and security component of Oracle Hyperion Data Relationship Management. An unauthenticated attacker who can reach the service over TCP can exploit a flaw that allows them to bypass authentication and achieve full control of the application. A successful exploitation results in the compromise of confidentiality, integrity, and availability of the entire Hyperion environment.
Affected Systems
The affected product is Oracle Hyperion Data Relationship Management version 11.2.25.0.000. No other versions are listed as vulnerable in the CNA information.
Risk and Exploitability
The base score of 9.8 indicates a critical severity. The vulnerability is easily exploitable without authentication and requires only network access to the affected ports. The EPSS score of 0.00358 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV; however, the high CVSS score and network-based attack vector imply that a determined adversary could still target it. The weakness is primarily an access control failure, where the attacker can bypass authentication checks.
OpenCVE Enrichment