Impact
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 contains an access‑and‑security flaw that permits any unauthenticated user with network connectivity to the product’s HTTP interface to bypass authentication and read critical data. The flaw is a direct ability to read data without legitimate credentials and does not support modification or deletion of data, limiting the impact to confidentiality compromise.
Affected Systems
The vulnerability affects Oracle Corporation’s Hyperion Data Relationship Management, specifically the 11.2.25.0.000 release. No other vendors, products, or versions are indicated in the CNA data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, and the description states the flaw is easily exploitable by attackers who can reach the Hyperion instance over HTTP. The EPSS score is listed as < 1 %, signifying a low but non‑zero exploitation probability, and the vulnerability is not included in the CISA KEV catalog, suggesting no currently reported active exploitation. Based on these metrics, the risk remains significant due to the remote unauthenticated attack vector and the potential for wide data exposure.
OpenCVE Enrichment