Impact
The vulnerability resides in the Access and Security component of Oracle Hyperion Data Relationship Management. A low‑privileged attacker who can reach the application over HTTP can, with the cooperation of another user, gain unauthorized read, insert, update, or delete access to sensitive data. This compromise can enable the attacker to potentially access all data available to the application, infringing on confidentiality and, in some cases, integrity, because the flaw permits escalation beyond the original low privilege level. The flaw is associated with CWE-352.
Affected Systems
Affected are Oracle Corporation’s Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability may also affect other Oracle applications that are integrated with Hyperion by way of shared authentication or data services, as indicated by the scope change flag.
Risk and Exploitability
The CVSS 3.1 base score of 7.6 indicates a high‑severity issue with significant confidentiality impact and a smaller integrity impact. The EPSS score is less than 1%, suggesting that active exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector requires network access over HTTP and a low privilege attacker, exploitation is technically doable but still needs social engineering or legitimate user cooperation. The scope change marker indicates that successful exploitation could spill over to other interconnected Oracle services, increasing overall risk.
OpenCVE Enrichment