Impact
The vulnerability in Oracle Hyperion Data Relationship Management is caused by improper access control in its Access and security component. A low‑privileged attacker who can reach the application over HTTPS can create, delete or modify data that should be restricted. This flaw compromises the confidentiality and integrity of all Oracle Hyperion data, allowing unauthorized changes or removal of critical information.
Affected Systems
The flaw affects Oracle Corporation’s Oracle Hyperion Data Relationship Management product, version 11.2.25.0.000. Any deployment of that version is vulnerable, and the scope change can enable similar attacks against other Oracle Hyperion products that share this component.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity. The attack vector is network‑based, exploiting a low‑privilege user over HTTPS and requiring user interaction. While the EPSS score is very low, the combination of remote access, low privilege, and potential scope expansion creates a significant risk for unauthorized data modification. The vulnerability is not yet listed in the CISA KEV. Patch availability should be verified, and until a patch is applied, the risk remains elevated.
OpenCVE Enrichment