Impact
The Oracle Hyperion Data Relationship Management component is vulnerable in its access and security logic. Based on the description, it is inferred that a low‑privileged attacker can exploit the flaw and bypass authentication or authorization checks, enabling read access to all data available from the server. This leads to a confidentiality breach, where an attacker receives critical business information. No data integrity or availability impact is noted in the official description, but the scope change indicates that the vulnerability might also affect other Oracle products that have the same flaw.
Affected Systems
The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The description also notes that the exploited weakness may change the scope to impact other Oracle products, though specific products are not listed in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 classifies the vulnerability as high severity, primarily affecting confidentiality. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the advisory is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over HTTP, with low complexity and low privileges required. Because the flaw resides in the Access and security component, an attacker can bypass authentication or authorization controls to read all data exposed by the server. The scope change mentioned suggests that similar flaws in other Oracle products could amplify the impact.
OpenCVE Enrichment