Impact
The vulnerability resides in Hyperion Data Relationship Management's access and security component. It permits an unauthenticated attacker who can reach the system over SMTP to alter access controls, thereby creating, deleting, or modifying access rights to critical data. This also allows the attacker to gain unauthorized access to the data itself, potentially obtaining full visibility over all stored assets. The weakness aligns with improper authentication and access control weaknesses, allowing breaches of confidentiality and integrity.
Affected Systems
Affected systems are Oracle Hyperion Data Relationship Management 11.2.26.0.000. Only this specific release is impacted, and all deployments running this version are susceptible regardless of their network posture.
Risk and Exploitability
The base CVSS score of 7.4 reflects high confidentiality and integrity impact with a high attack complexity. EPSS indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in CISA KEV catalog. Despite the low exploitation likelihood, the attack vector requires only network access via SMTP, and the absence of authentication makes exploitation straightforward once the attacker reaches the environment.
OpenCVE Enrichment