Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data governance and analytics platform used by large organizations to manage critical business information relationships and security policies. An unauthenticated attacker can exploit a flaw in the access control component over the network to gain complete control of the system, potentially leading to unauthorized access to sensitive business data, manipulation of data relationships, and service disruption.
Technical details
This is an authentication bypass vulnerability in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable and requires no authentication or user interaction; an attacker with network access to the affected TCP service can trigger the flaw remotely. Successful exploitation grants complete system takeover, allowing the attacker to compromise confidentiality, integrity, and availability of all data and functions managed by the platform. Patch availability should be verified through Oracle's official security patch advisory channels.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed