Impact
The vulnerability is in the access and security component of Oracle Hyperion Data Relationship Management. A low‑privilege attacker with network access via HTTP can exploit this flaw to read or modify data that should be protected. Successful exploitation results in unauthorized access to critical data and the ability to insert or delete data, compromising confidentiality and integrity of the system.
Affected Systems
The flaw affects Oracle Hyperion Data Relationship Management version 11.2.26.0.000. Users running this version on any installation exposed to the network are at risk. No other versions or components are known to be affected.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 7.1, indicating a high severity with high confidentiality impact. The EPSS score is under 1%, suggesting a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote over HTTP, requiring only low‑privilege credentials or no credentials, and no user interaction.
OpenCVE Enrichment