Impact
The vulnerability resides in the Access and security component of Oracle Hyperion Data Relationship Management. It allows a low privileged attacker who can reach the system over TCP to obtain unauthorized access to critical data, exposing the confidentiality of all data accessible through the application. The weakness is an improper access control flaw that lets the attacker bypass normal authentication or authorization checks. This can lead to full data exposure but does not affect integrity or availability directly.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The affected product is Oracle Hyperion Data Relationship Management and any related components that rely on its access control functionality. The vulnerability applies to the 11.2.26.0.000 release only.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, especially with a confidentiality impact. The EPSS score is less than 1%, implying that the likelihood of observed exploitation in the wild is low, but the vulnerability still represents a serious risk due to the potential data exposure. The CVE is not listed in the CISA KEV catalog, but the nature of the flaw means that an attacker could use it to gain unauthorized data access from a remote machine. The attack vector is network based, requiring TCP connectivity to the vulnerable application, and permits low privileged attackers to leverage the flaw to bypass normal access controls.
OpenCVE Enrichment