Impact
A flaw in Oracle Hyperion Data Relationship Management allows a low‑privileged attacker with network access to the HTTP interface to fully compromise the application. The vulnerability can affect confidentiality, integrity, and availability, enabling an attacker to take over the system. It is an access‑control weakness that permits privilege escalation through insufficient authentication and authorization checks.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management version 11.2.25.0.000 is affected, as stated in Oracle’s advisory. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects high impact and remote exploitation with no user interaction. The EPSS score is < 1%, which indicates a very low but non‑zero probability the vulnerability will be exploited. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker sending crafted HTTP requests to the application, requiring only low privileges; if successful, the attacker could gain full control of the system.
OpenCVE Enrichment