Executive brief
Oracle Hyperion Data Relationship Management is a data integration and governance platform used by enterprises to manage critical business information. An unauthenticated attacker can bypass security controls and gain complete access to the system over the network, allowing them to view, modify, or delete sensitive business data without authorization.
Technical details
This is an authentication bypass vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability is easily exploitable and requires no user interaction; an unauthenticated attacker with network access via HTTP can bypass authentication controls to gain unauthorized access. Successful exploitation allows complete read and write access to critical data stored in the system. The vulnerability affects all accessible data in the platform and has both confidentiality and integrity impacts.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed