Impact
This vulnerability resides in the Access and security component of Oracle Hyperion Data Relationship Management and results in remote code execution and full compromise of the system. An attacker with low privileges and network access can exploit the weakness over HTTP to gain complete control, leading to confidentiality, integrity, and availability losses.
Affected Systems
Affected vendor: Oracle Corporation. Product: Oracle Hyperion Data Relationship Management. Version: 11.2.25.0.000. The vulnerability is documented for this specific build and does not apply to other releases.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.8 indicates severe risk. The EPSS score of 0.00328 (0.3%) suggests a very low probability of exploitation, but the impact remains extreme. The weakness allows attackers with low privileges and network access via HTTP to exploit the vulnerability without requiring additional privilege escalation. The vulnerability is not yet listed in the CISA KEV catalog, and the high impact together with the ease of exploitation warrant prompt remediation. The likely attack vector is through the HTTP interface.
OpenCVE Enrichment