Impact
A vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management permits a low-privileged attacker who can reach the application over HTTP to compromise the system. The flaw is easily exploitable and can lead to full system takeover, affecting confidentiality, integrity and availability.
Affected Systems
Vulnerable version is Oracle Hyperion Data Relationship Management 11.2.25.0.000, distributed by Oracle Corporation. No other versions were listed as affected.
Risk and Exploitability
The CVSS base score of 8.8 and an EPSS score of less than 1% do not mean exploitation is unlikely; the flaw is actively exploitable over standard HTTP without authentication. Because it grants a low-privileged attacker the ability to gain full control, the risk is considered high. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits are recorded yet, but the attack scenario requires only network access to the vulnerable port and no special credentials, implying a straightforward exploitation path.
OpenCVE Enrichment