Impact
The vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000 allows an unauthenticated attacker to create, modify, or delete critical data. The lack of proper access control enables full unauthorized control over the system’s data violations without affecting availability.
Affected Systems
Oracle Corporation’s Oracle Hyperion Data Relationship Management product is affected. Only version 11.2.26.0.000 is known to be vulnerable according to the vulnerability description and the listed CPE string.
Risk and Exploitability
The CVSS base score of 7.4 indicates a high severity rating, with a network attack vector, high attack complexity, no required privileges, and no user interaction. The EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker with TCP network access can exploit the flaw directly to alter or delete data managed by the product.
OpenCVE Enrichment