Impact
The Oracle Hyperion Data Relationship Management product contains an access and security flaw that can be exploited by an attacker who has a low‑privileged account on the same host. Successfully leveraging this weakness gives the attacker full control over the Hyperion application, resulting in complete loss of confidentiality, integrity, and availability.
Affected Systems
The affected version is 11.2.25.0.000, delivered by Oracle Corporation. Any deployment of this product that resides on a host where a low‑privileged local user exists is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 indicates high severity. The attack vector is local (AV:L) and requires low privileges (PR:L). The attack complexity is high, meaning that exploitation is not trivial, but the potential for application takeover makes it a significant risk. EPSS is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in CISA KEV. Despite these factors, the high impact necessitates prompt remediation.
OpenCVE Enrichment