Executive brief
Oracle Hyperion Data Relationship Management is a critical enterprise financial planning and data integration system used by large organizations. A vulnerability in the access and security component allows a high-privileged attacker with network access to completely take over the system, potentially compromising sensitive financial data and operations across connected systems.
Technical details
This is an access control vulnerability in the Oracle Hyperion Data Relationship Management component (version 11.2.25.0.000) exploitable over HTTPS by a high-privileged attacker with network access. The vulnerability permits complete compromise of the affected system—including confidentiality, integrity, and availability impacts—and has a scope change designation indicating attacks may significantly impact additional interconnected products. The attack requires high privilege level but no user interaction; patches or workarounds availability is not detailed in available sources.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed