Impact
A flaw in the access and security component of Oracle Hyperion Data Relationship Management allows an attacker who can reach the system over HTTP to create, delete, or alter critical data without authentication. The vulnerability results in significant confidentiality and integrity breaches, permitting unauthorized users to modify or read sensitive information. The weakness is rooted in improper access control wherein the system fails to verify the identity of requesting users before processing critical actions.
Affected Systems
The only affected product is Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, as identified by Oracle’s CNA. The vulnerability exists in all installations of that specific release and is not known to affect other versions or similar products.
Risk and Exploitability
The CVSS 3.1 score of 8.1 indicates substantial impact on confidentiality and integrity, while the attack vector is network-based via HTTP. Successful exploitation requires an unauthenticated attacker with network access and human interaction from a user other than the attacker, such as a phishing or social‑engineering step. The EPSS score of less than 1% indicates a low probability of exploitation, yet combined with the CVSS score the vulnerability remains a high‑priority issue. The advisory is not listed in the CISA KEV catalog, suggesting the attack is not yet widely observed but remains a significant concern.
OpenCVE Enrichment