Impact
The vulnerability arises in the Access and Security component of Oracle Hyperion Data Relationship Management and permits an unauthenticated attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of data, and to gain access to all data stored in the system. This results in severe confidentiality and integrity compromise, as the attacker can read or alter critical information. The weakness is due to missing or improper authentication checks, mapping to CWE-287 and CWE-306.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.26.0.000, is affected. No other versions or products are listed as impacted. The vulnerability is specific to the Access and Security component deployed by the vendor.
Risk and Exploitability
The CVSS 3.1 base score is 9.1, indicating high magnitude with significant confidentiality and integrity impact. The EPSS score is below 1%, suggesting current observed exploitation activity is very low, but the description explicitly labels it as easily exploitable. It is not listed in CISA’s KEV catalog. The likely attack vector involves an unauthenticated HTTP request sent by an adversary over the network, requiring no privileged access or authentication. The attacker can fully control the affected instance until mitigation steps are applied.
OpenCVE Enrichment