Impact
Vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000 allows a low‑privileged attacker who can reach the application over HTTP to compromise the system. Although the flaw is difficult to exploit, successful exploitation grants full control of the application, enabling the attacker to read, modify, or delete data and to take over the service. The resulting impact spans confidentiality, integrity, and availability, given that the system holds sensitive organizational information.
Affected Systems
Only Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is listed as affected. The vendor is Oracle Corporation. The advisory notes a scope change that could affect additional products if those products are integrated with the compromised instance.
Risk and Exploitability
The vulnerability’s CVSS v3.1 base score is 8.5, indicating a high severity risk. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation, and the CVE is not listed in the CISA KEV catalog, implying no known public exploits yet. The attack vector is network‑based; an attacker needs only HTTP access and low privileges, making the attack surface sizable. Because the flaw changes the scope, a successful attack may also impact other products that interact with the compromised Hyperion deployment.
OpenCVE Enrichment