Impact
The vulnerability resides in the access and security component of Oracle Hyperion Data Relationship Management. It permits a low‑privileged attacker with network HTTP access to create, delete, or modify data, thereby undermining confidentiality and integrity of the system.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management version 11.2.25.0.000 is affected. The flaw is limited to this release but may impact other Oracle Hyperion products that share the same component.
Risk and Exploitability
With a CVSS 3.1 base score of 8.7, the flaw is high severity. The likely attack vector requires HTTP network access, low privileges, user interaction from someone other than the attacker, and involves a change of scope. Because the EPSS score is 0.00323 (about 0.32%) and the vulnerability is not listed in the CISA KEV catalog, the risk remains high due to the severe potential impact, but the likelihood of exploitation is low yet non‑zero. Successful exploitation could result in unauthorized data creation, deletion, or modification, and could grant full access to all accessible data.
OpenCVE Enrichment