Impact
A flaw in the Oracle Hyperion Data Relationship Management access and security component allows an unauthenticated attacker who can log on to the infrastructure hosting the application to create, delete, or modify critical data. This leads to a loss of data integrity and confidentiality, enabling unauthorized manipulation of all data available through the application. The weakness is consistent with improper access control (CWE-284).
Affected Systems
The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.25.0.000. No other vendors or versions are presently listed as affected.
Risk and Exploitability
The CVSS3.1 score of 7.7 indicates high impact to confidentiality and integrity but no availability loss. The EPSS score of 0.00162 (less than 1%) indicates a very low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. However, the attack vector is local (AV:L) and requires no pre‑existing privileges (PR:N), making the exploit path straightforward for any user who can access the infrastructure where Hyperion runs.
OpenCVE Enrichment