Impact
The vulnerability in Oracle Hyperion Data Relationship Management is an access‑control flaw that lets a low‑privileged user create, delete, or modify data access permissions, thereby breaking confidentiality and integrity of critical data.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 for all affected instances running on the organization's infrastructure.
Risk and Exploitability
The CVSS 3.1 score of 7.1 indicates a high‑severity weakness, but the exploit is limited to attackers who already have local logon to the host running the application. No public exploit is available and the vulnerability is not listed in CISA KEV, though its EPSS score is <1%. The risk remains significant for environments where users have local access to the application server, as the attacker can gain full data‑level control without needing elevated privileges.
OpenCVE Enrichment