Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data integration and metadata management platform used by organizations to manage complex data relationships. An unauthenticated network-accessible vulnerability allows attackers to completely compromise the system, potentially gaining full control over data assets, integrity, and availability—a critical risk to business operations and data security.
Technical details
An easily exploitable vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access via TCP to completely compromise the affected system. The vulnerability does not require user interaction or special conditions (AC:L/PR:N/UI:N). Successful exploitation results in full takeover of the application, with impacts across confidentiality, integrity, and availability. The affected version is 11.2.25.0.000; patch availability should be verified through Oracle's security advisories.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed