Impact
A flaw in the access and security component of Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with network access to the SOAP interface to cause a hang or a repeatable crash of the application, which results in a complete denial of service. The vulnerability is classified as CWE‑400 and carries a CVSS 3.1 base score of 7.5, indicating a high availability impact.
Affected Systems
The affected product is Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, supplied by Oracle Corporation.
Risk and Exploitability
Because the flaw can be triggered from the network without authentication and the EPSS score is less than 1 %, the practical likelihood of exploitation is considered low, but the impact is severe if an attack succeeds. The vulnerability is not listed in CISA’s KEV catalog; however, an attacker who controls the remote SOAP endpoint could repeatedly crash the application, causing significant downtime.
OpenCVE Enrichment