Impact
A flaw in Oracle Hyperion Data Relationship Management allows an unauthenticated attacker with network access to the HTTP interface to modify data, read privileged information, and trigger a partial denial of service. The vulnerability arises during the access and security component handling of requests, enabling the attacker to perform unauthorized update, insert, or delete operations as well as read restricted data sets. The impact includes loss of confidentiality, integrity, and availability, as reflected in the CVSS score of 7.3.
Affected Systems
Oracle Hyperion Data Relationship Management version 11.2.26.0.000, sold by Oracle Corporation, is the only version affected according to the vendor advisory.
Risk and Exploitability
Given the base score of 7.3, the exploit requires low effort (no authentication, low complexity) and is reachable over the network via HTTP. The EPSS score of less than 1% suggests that, while exploitation is possible, it is currently not widely observed. The vulnerability is not listed in CISA’s KEV catalog, but its potential to alter data and disrupt service makes it a high risk that could be leveraged by adversaries with sufficient network reach.
OpenCVE Enrichment