Impact
This vulnerability resides in the access and security component of Oracle Hyperion Data Relationship Management. It allows an attacker with high privileges and network access to HTTP traffic to gain unauthorized access to all data stored in the application and to edit, insert, or delete that data. The impact includes confidentiality loss for critical data and potential integrity compromise.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management product, version 11.2.26.0.000, is affected. No other vendor variants or versions are indicated at this time.
Risk and Exploitability
The CVSS core score of 7.6 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N) indicates high confidentiality impact and a lower integrity impact, with a scope change making the vulnerability affect more than the initially affected component. The EPSS score is very low (< 1%), meaning that the demonstrated exploitation probability is small, but the attack can still be carried out by a skilled adversary with network access. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Attackers would need to reach the application over HTTP, supply crafted requests, and exploit the privilege escalation to gain full administrative control of the data stored within Hyperion.
OpenCVE Enrichment