Impact
This vulnerability resides in the Access and Security component of Oracle Hyperion Data Relationship Management and allows a low‑privileged attacker with network access to the HTTP interface to read, insert, or delete data that should be restricted. The weakness is an improper access control flaw (CWE‑284) combined with unguarded error handling (CWE‑863), enabling unauthorized confidentiality and integrity impacts. Successful exploitation can expose critical data or fully compromise all accessible data within the application.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.26.0.000 is the only version identified as affected by this advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 reflects a medium‑to‑high severity, and the EPSS score indicates that exploitation is predicted to be rare. However, the attack vector is network (AV:N), attack complexity is low (AC:L), and the required privilege is low (PR:L) with user interaction (UI:R). The advisory notes the scope change (S:C), meaning the impact could extend to other products. Overall, the risk remains significant for environments that expose the service to the internet or lack strict access controls.
OpenCVE Enrichment