Impact
The vulnerability stems from a failure in the access control mechanisms within the Oracle Hyperion Data Relationship Management component. An attacker with low privileges and network access via HTTP can exploit this flaw to bypass authorization checks, enabling unauthorized creation, deletion, or modification of critical data and user permissions. The resulting changes compromise data confidentiality and integrity without providing remote code execution capabilities.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 is affected. No other product versions are listed as impacted, though the scope of the vulnerability may extend to other related Oracle Hyperion products.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.2 indicates a high severity vulnerability with significant confidentiality and integrity impacts. Exploitation does not require special privileges beyond low-level access and is reachable through standard HTTP traffic. The EPSS score is < 1%, indicating a very low probability of exploitation, although the vulnerability is not listed in CISA’s KEV catalog, so no widespread active exploitation is known. Attackers would need to identify and connect to the Oracle Hyperion Data Relationship Management web interface from a network that can reach it.
OpenCVE Enrichment