Impact
The flaw in Oracle Hyperion Data Relationship Management permits an attacker to send SOAP requests without authentication, enabling the creation, deletion, or alteration of data and unrestricted data viewing. This unauthorized data manipulation compromises both confidentiality and integrity of all data accessible through the affected system, as reflected by the CVSS vector that flags high impacts on confidentiality and integrity.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is affected. Any environment running this specific version of the product is vulnerable and requires immediate verification and remediation.
Risk and Exploitability
The CVSS base score of 9.1 demonstrates a high severity level, and the vulnerability is exploitable remotely via network traffic to the SOAP endpoint with no authentication or user interaction needed. The EPSS score of 0.00398 (less than 1%) indicates a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. Yet the combination of a remote attack vector, low attack complexity, and total data access presents a critical risk that demands urgent action.
OpenCVE Enrichment