Impact
The vulnerability in Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with network access via HTTP to create, modify, or delete critical data objects and to gain reading access to all data. This flaw stems from improper access control within the Access and Security component, enabling attackers to bypass authentication and perform privileged actions. It is an example of Improper Access Control (CWE‑284), leading to severe impacts on confidentiality and integrity.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.25.0.000, is the affected product. No other versions are reported as vulnerable, which is inferred from the available data.
Risk and Exploitability
The risk is high, reflected by the CVSS score of 9.1. The EPSS score of < 1% indicates a very low, but nonzero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw over HTTP without authentication, indicating a likely network or internet attack vector. External references point to an Oracle security advisory detailing a patch for this version.
OpenCVE Enrichment