Impact
The vulnerability resides in the Access and Security component of Oracle Hyperion Data Relationship Management. Because authentication is bypassed, an attacker who can reach the service over HTTP can read confidential data, or in the worst case gain full visibility into all data stored by the product. The flaw is not a code‑execution bug but a data‑exposure flaw that fully compromises confidentiality with no configuration restrictions described.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management product, release 11.2.25.0.000. No other versions or platforms are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects a high likelihood of exploitation (Av:N, Ac:L, Pr:N). The attack can be launched from any network location that can contact the HTTP endpoint, and no authentication or elevated privileges are required. The EPSS score of 0.00416 (approximately 0.4%) indicates a very low exploitation probability, but the vulnerability is not listed in the CISA KEV catalog, and the high severity and unauthenticated nature suggest it is a priority for remediation.
OpenCVE Enrichment