Impact
A flaw in the access-and-security component of Oracle Hyperion Data Relationship Management enables an unauthenticated attacker who can reach the system over HTTPS to create, delete, or modify access to critical data. The vulnerability also can cause a partial denial of service by disrupting access to the application. The weakness lies in improper access control, allowing the attacker to obtain elevated rights without prior authentication, as reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L.
Affected Systems
The product affected is Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, from Oracle Corporation. Only this specific build is listed as vulnerable; no other versions or products are currently known to be impacted.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity impact on integrity and availability. The EPSS score of less than 1% suggests a very low probability of recent exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. However, the required user interaction implies that an attack would rely on social engineering to compel a legitimate user to log into the system and execute the malicious payload. Once the user performs the interaction, the attacker can manipulate privileged data and potentially disrupt service. Consequently, while exploitation is possible, it would likely involve coordinated social engineering rather than an automated attack.
OpenCVE Enrichment