Impact
Oracle Hyperion Data Relationship Management is vulnerable to an easily exploitable flaw in its Access and security component. An attacker who can reach the system through HTTPS can gain unauthorized access to critical data and, in some cases, modify or delete that data. The vulnerability can result in a loss of confidentiality of the data exposed by the system, with only a minimal impact on integrity.
Affected Systems
Products affected are Oracle Hyperion Data Relationship Management version 11.2.25.0.000. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS v3.1 score of 8.2 indicates a high severity with a high confidentiality impact and a low integrity impact. The EPSS score is <1%, indicating a very low but nonzero exploitation probability, yet the vulnerability is reported as easily exploitable and requires only network access via HTTPS. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is over the network via HTTPS, and that unauthenticated users can trigger the vulnerability to compromise the system.
OpenCVE Enrichment