Impact
The flaw lives in the Access and Security component of Oracle Hyperion Data Relationship Management and permits a high privileged attacker with network access via HTTP to create, delete or alter critical data. Affected data may include all records accessible through the product; confidentiality and integrity are compromised. Because the vulnerability can change the overall scope, other Oracle Hyperion applications may also be impacted.
Affected Systems
Oracle Hyperion Data Relationship Management, version 11.2.26.0.000, is affected. The vulnerability may also impact additional Oracle Hyperion products due to a scope change that extends the reach of the flaw beyond the original product.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 signals high overall impact, while the EPSS score of less than 1% indicates that exploitation is at present considered unlikely. The vulnerability is not listed in the CISA KEV catalog. Its remote network exposure and requirement for high privileged access mean that the risk is non‑negligible even though successful exploitation is rare. If an attacker succeeds, they could fully subvert data integrity and availability within the affected Hyperion environment.
OpenCVE Enrichment