Impact
A vulnerability in the access and security component of Oracle Hyperion Data Relationship Management allows a low‑privileged attacker who can reach the system over HTTP to compromise the application and potentially take it over. Successful exploitation would give the attacker full control, impacting confidentiality, integrity, and availability of the data managed by the system.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.25.0.000, is affected. No other versions are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high severity impact. The EPSS score of less than 1% shows a low probability of current exploitation. The network‑based attack vector with only a low‑privileged account makes the vulnerability attractive for attackers; this attraction is inferred from the described conditions. The vulnerability is not listed in CISA’s KEV catalog, although its ease of exploitation makes it a potential future target.
OpenCVE Enrichment