Impact
Oracle Hyperion Data Relationship Management contains a flaw in its access and security component that allows an attacker with low privileges and simple network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover of the product, resulting in loss of confidentiality, integrity, and availability for all data managed by the system.
Affected Systems
The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.26.0.000. No other affected versions are currently listed in the available data.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity, while the EPSS score of <1% reflects a low probability of exploitation in the current threat landscape. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a remote, network-based HTTP request; an attacker requires only low privileges to successfully compromise the application and potentially gain unrestricted access to the Hyperion instance.
OpenCVE Enrichment