Impact
Oracle Hyperion Data Relationship Management contains an access‑and‑security flaw that allows a high‑privileged attacker with network access over HTTPS to compromise the system. A successful exploit can lead to complete takeover of the Hyperion application and, because of scope change, may also affect other connected Oracle products. The vulnerability is easily exploitable and causes full confidentiality, integrity, and availability loss for affected instances.
Affected Systems
The affected product is Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.25.0.000. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high severity risk. Exploitation requires only network connectivity to the HTTPS port, and the attack vector is considered networkable. The EPSS score of < 1% indicates a very low probability of exploitation in the general population, yet the flaw remains exploitable. The lack of listing in CISA KEV does not reduce the intrinsic risk posed by the vulnerability. Given the severity and ease of exploitation, it is likely that this vulnerability would be used in real‑world attacks against exposed Hyperion installations.
OpenCVE Enrichment