Impact
A flaw in the access and security component of Oracle Hyperion Data Relationship Management permits a low‑privileged attacker who can reach the system over HTTP to potentially gain unauthorized read or write access to protected data. The vulnerability would allow the attacker to bypass normal authorization controls and could result in the disclosure of confidential information, or the unauthorized update, insertion, or deletion of data within the system. The vulnerability is marked as ‘easily exploitable’ and involves a low complexity attack, however it requires the attacker to have an additional human user interact with the system, implying it is not a purely automated attack.
Affected Systems
The vulnerability affects Oracle’s Hyperion Data Relationship Management version 11.2.26.0.000. No other product versions are listed as impacted, but analysts note that an exploit could have broader effects on connected Oracle Hyperion applications if the same access control weakness exists elsewhere.
Risk and Exploitability
The CVSS score of 7.6 reflects moderate to high confidentiality impact and a low integrity impact, with a change of scope because the flaw could allow an attacker to affect data that was not originally in their scope. The EPSS score of < 1% indicates the likelihood of exploitation is currently very low but not zero. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread zero‑day exploitation. Attackers would need network access to the application over HTTP and would need a legitimate user to interact with the system on their behalf. The actual exploitation would involve triggering a flaw in the authorization logic that bypasses proper access controls, granting the attacker further actions on the data exposed by the application.
OpenCVE Enrichment