Impact
Local attacker with low-level privileges on the server hosting Oracle Hyperion Data Relationship Management can exploit a flaw in the Access and Security component to gain unauthorized access to the system. The vulnerability allows the attacker to read data that is normally restricted to higher privileged users, with the potential to view all data exposed by the application. The breach would compromise the confidentiality of the organization’s sensitive information but does not directly lead to integrity or availability disruption.
Affected Systems
The affected product is Oracle Hyperion Data Relationship Management, version 11.2.25.0.000. Because the vulnerability includes a scope change, successful exploitation could also impact other applications or services that share the same infrastructure or data sources, extending the attack surface beyond the single product.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 classifies the issue as a moderate severity flaw. Exploitation requires local logon to the infrastructure but only low privileges, with no user interaction needed. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who has already gained access to the host through other means, such as phishing or exploiting other local weaknesses, and then uses this flaw to harvest confidential data.
OpenCVE Enrichment