Impact
The vulnerability resides in a component responsible for access and security. An attacker who is only lightly privileged and can reach the system over HTTP can compromise the product, leading to full takeover. The effect is significant, compromising all confidential information and the integrity and availability of the service.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.26.0.000 is affected. This includes installations that expose the HTTP interface for the product.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high severity, with impacts to confidentiality, integrity, and availability. The EPSS score is below 1%, suggesting low current exploitation likelihood, but the attack vector is network‑based, requires only low privileges, and no user interaction, making it potentially easy to leverage once discovered. The vulnerability is not listed in CISA KeV, so no public exploits are confirmed yet, but monitoring and quick patching remain critical.
OpenCVE Enrichment