Impact
A vulnerability in the Oracle Hyperion Data Relationship Management product’s access and security component allows a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized viewing of critical data as well as insertion, update, or deletion of accessible data, thus affecting confidentiality and integrity. The CVSS 3.1 Base Score of 7.1 reflects these impacts.
Affected Systems
Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, is the only product impacted by this issue.
Risk and Exploitability
The vulnerability is rated at a moderate‑to‑high severity (CVSS 7.1) but has a low likelihood of exploitation indicated by an EPSS score of less than 1%. It is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker with low privileges connecting over HTTP to the affected system. Because the flaw resides in the access and security component, an attacker who can reach the HTTP interface can gain unauthorized access or modify data without needing elevated privileges.
OpenCVE Enrichment