Impact
A flaw in the Access and security component of Oracle Hyperion Data Relationship Management permits an unauthenticated attacker to trigger a persistent denial of service over HTTP. The vulnerability is a manifestation of uncontrolled resource consumption, classified as CWE-400, leading the application to hang or crash so that it cannot respond to legitimate requests.
Affected Systems
Oracle Corporation’s Hyperion Data Relationship Management, version 11.2.26.0.000, is the only supported build listed as affected. No other versions or components were identified as vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on availability, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. Because the flaw is exploitable without authentication and can be triggered via standard HTTP requests, it poses a significant risk to organizations that expose the application to the network. The vulnerability is not listed in CISA KEV, but its availability impact and the lack of authentication prerequisites increase its urgency for remediation.
OpenCVE Enrichment