Impact
The vulnerability in Oracle Hyperion Data Relationship Management’s Access and security component allows an unauthenticated attacker with ordinary network access over HTTP to create, delete or modify critical data, and to read all data managed by the application. This flaw isAuthentication) and CWE‑306 (Missing Authentication). Successful exploitation results in complete compromise of data confidentiality and integrity, granting the attacker full control over critical information.
Affected Systems
Affected systems are Oracle Hyperion Data Relationship Management version 11.2.26.0.000, part of Oracle’s Hyperion product suite. The vulnerability applies only to this specific build; earlier or later releases are not listed as affected by the current CNA data.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 9.1, indicating high impact on confidentiality and integrity. The EPSS score is listed as less than 1 %, suggesting a very low but non‑zero probability of exploitation in the wild. The attacks require only unauthenticated HTTP access, any exposed instance. Although not yet catalogued by CISA’s KEV list, the combination of a high severity score and an easily exploitable remote vector creates a significant risk for organizations that expose the Hyperion application to the Internet or shared networks.
OpenCVE Enrichment