Impact
A SQL injection flaw combined with insufficient access control (CWE‑284) allows a low‑privileged attacker who can reach the SQL endpoint of Oracle Hyperion Data Relationship Management to execute arbitrary queries. The attacker can create, delete, or modify critical data and read all data the application can see, leading to confidentiality and integrity impacts. The CVSS v3.1 vector shows a high severity score of 8.2. The flaw requires only a low‑privilege account with network access to the database, which increases the likelihood of exploitation.
Affected Systems
Oracle Corporation’s Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. The advisory indicates that this is the only supported version affected; other Hyperion products are not listed as directly vulnerable, though the description notes a possible scope change affecting additional products.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity flaw. The EPSS score is listed as less than 1 %, suggesting very low current exploit activity, yet the weakness exists and could be used by internal users or adversaries with network access to the SQL interface. Because the attack requires only a low‑privilege account, it is likely to succeed if proper controls are not in place. The flaw is not yet tracked in the CISA KEV catalog, but its impact warrants prompt remediation.
OpenCVE Enrichment