Impact
The flaw resides in the access‑and‑security component of Oracle Hyperion Data Relationship Management. It permits a low‑privileged attacker with HTTP network access to gain unauthorized read, update or delete capabilities against data that the application serves. This is due to improper access control (CWE‑284) and privilege escalation (CWE‑863). The impact is therefore significant confidentiality and integrity compromise for the data exposed by the platform.
Affected Systems
Affected systems include Oracle Hyperion Data Relationship Management version 11.2.26.0.000, the only version listed as impacted. The product is widely deployed for enterprise data governance, reporting, and analytics, making the vulnerability relevant to organizations reliant on these capabilities.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 reflects high severity with a strong confidentiality impact. The EPSS score is reported as less than 1%, suggesting that real‑world exploitation is currently unlikely but not impossible. Successful attacks require an attacker with low privileges to reach the application over HTTP and a user other than the attacker to provide interaction—likely through social engineering or a compromised account. The loss of confidentiality and integrity could extend to other products due to the scope change noted in the description, and the vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment