Impact
The flaw is in the access and security component of Oracle Hyperion Data Relationship Management. A low‑privileged attacker who can reach the system over HTTP can leverage the vulnerability to create, delete, or modify critical data or gain unauthorized access to all data exposed by the application. This results in compromise of confidentiality and integrity; the attacker can alter or delete records, potentially causing business disruption or data loss. The weakness is a classic improper access control problem.
Affected Systems
Oracle Hyperion Data Relationship Management 11.2.25.0.000 is affected. No other versions are listed as vulnerable. The vulnerability pertains to the access and security module of this product.
Risk and Exploitability
With a CVSS base score of 8.1, the vulnerability is high severity, offering low attack complexity and user interaction but requiring low privileges. The attack vector is network over HTTP, so an attacker only needs network access to the instance. The EPSS score is less than 1%, indicating a low but nonzero likelihood of exploitation; it is not listed in the CISA KEV catalog. Given the confidentiality and integrity impacts, an exploited vulnerability could enable an adversary to modify or delete critical data, potentially disrupting business operations or causing data loss.
OpenCVE Enrichment