Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management platform used for managing business data relationships. An unauthenticated attacker can exploit a vulnerability in the Web Client's Unicode handling to gain unauthorized access to sensitive data and cause service disruptions without requiring valid credentials or user interaction.
Technical details
The vulnerability is an easily exploitable authentication bypass in the Web Client component of Oracle Hyperion Data Relationship Management (version 11.2.23.0.000). It resides in Unicode processing logic and is reachable over the network via HTTP without authentication required. An attacker can leverage this to access critical data within the system and trigger partial denial of service conditions. The attack has a low attack complexity, requires no privileges or user interaction, and impacts the entire system rather than just a single user context.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.23.0.000
Timeline
- 2026-08-18: disclosed