Impact
The vulnerability is a CWE-284 Access Control Vulnerability that resides in the access and security component of Oracle Hyperion Data Relationship Management. An attacker with network connectivity via TCP can gain unauthenticated control. Successful exploitation can lead to full takeover, compromising confidentiality, integrity, and availability of the system and potentially other integrated products due to a scope change.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is affected. No other product versions are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating the highest severity. The EPSS score is < 1%, suggesting a very low likelihood of exploitation. The CVE is not listed in the CISA KEV catalog. Attack vectors are network-based, utilizing TCP, with no authentication required, giving an attacker full control of the system should the vulnerability be exploited.
OpenCVE Enrichment