Impact
The flaw resides in the Access and security component of Oracle Hyperion Data Relationship Management. A user with only local or network‑bound privileges can exploit the vulnerability through standard HTTP traffic. Successful exploitation allows the attacker to fully compromise the application, leading to a complete takeover of confidentiality, integrity and availability. The weakness is a classic access control failure.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management version 11.2.25.0.000 is the single affected product; no other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a severe risk, while the EPSS score of < 1% suggests that exploit activity is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the affected component over HTTP with only a low privilege account, making the flaw attractive for adversaries who can expand the compromise to full system takeover once inside the application.
OpenCVE Enrichment