Impact
A flaw in Oracle Hyperion Data Relationship Management version 11.2.25.0.000 allows an unauthenticated attacker to send HTTP requests that bypass the system’s authentication controls and obtain any data stored by the application, resulting in a confidentiality breach.
Affected Systems
The vulnerability affects Oracle Hyperion Data Relationship Management 11.2.25.0.000, a product distributed by Oracle Corporation, and no other versions or products are listed as impacted.
Risk and Exploitability
The base CVSS score of 7.5 indicates a moderate‑to‑high risk, with an attack vector of network (AV:N), low authentication (PR:N), and no user interaction required (UI:N). The EPSS score is less than 1 %, and the vulnerability is not yet listed in the CISA KEV catalog, yet the straightforward HTTP exploitation path makes automated attacks feasible if an attacker can reach the service from the network.
OpenCVE Enrichment