Impact
The vulnerability permits an unauthenticated attacker with network access over HTTP to compromise Oracle Hyperion Data Relationship Management. It allows unauthorized creation, deletion, or modification of critical data, as well as full access to all data exposed by the system, causing significant confidentiality and integrity loss. The weakness affects the access and security component, and the scope change indicates that other Oracle products might also be impacted.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Hyperion Data Relationship Management, specifically version 11.2.25.0.000. The access and security component is the focal point, and the described scope change suggests that additional Oracle products could be vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 reflects high severity with confidentiality and integrity impacts. EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated and reachable over HTTP, an attacker can potentially exploit it from the network, but the low EPSS suggests that relevant exploit code may not yet be widespread.
OpenCVE Enrichment