Impact
The vulnerability resides in the access and security component of Oracle Hyperion Data Relationship Management and represents an authentication and authorization weakness. An unauthenticated attacker with network presence can send crafted HTTP requests to the application and cause the creation, deletion or modification of critical data. Because the vulnerability bypasses authentication safeguards, the attacker can gain full control over data stored in the Hyperion instance. The resulting damage includes loss of confidentiality and integrity for all data accessible via the product.
Affected Systems
Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score is 9.1, classifying the flaw as critical. The exploit requires only a network connection over HTTP and does not need user credentials or elevated privileges. The EPSS metric is lower than 1 percent, and the issue is not listed in the CISA KEV catalog, but the combination of high score and easy network exploitation presents a significant threat, especially in environments where Hyperion is exposed to untrusted networks.
OpenCVE Enrichment