Impact
Oracle’s Hyperion Data Relationship Management contains an access‑and‑security flaw that allows an unauthenticated attacker with network access to the application over HTTP to gain access to all data stored or cached by the system. The vulnerability targets version 11.2.26.0.000 and is classified as a remote, unauthenticated data‑disclosure flaw. The CVSS 3.1 base score of 7.5 reflects a high impact on confidentiality while integrity and availability remain unaffected.
Affected Systems
The only affected product is Oracle Hyperion Data Relationship Management version 11.2.26.0.000. No other releases or companion products are listed as vulnerable.
Risk and Exploitability
Because the flaw is triggered by any HTTP request sent to the exposed interface, an attacker can exploit it from any network location that can reach that endpoint. The CVSS 3.1 base score of 7.5 indicates a high severity level for confidentiality impact, while integrity and availability remain unaffected. The EPSS score of less than 1 % indicates that widespread automated attacks have not yet been observed. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the remote and unauthenticated nature of the attack combined with the high confidentiality impact make it a moderate‑to‑high risk for organizations that expose the Hyperion instance.
OpenCVE Enrichment