Executive brief
Oracle Hyperion Data Relationship Management is an enterprise financial planning and consolidation platform used by organizations to manage complex financial data relationships. A vulnerability in its access control and security component allows a low-privileged authenticated user to gain complete control over the system, potentially compromising all data confidentiality, integrity, and system availability.
Technical details
This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management (DRM) version 11.2.25.0.000. The flaw allows a low-privileged attacker with valid network credentials to authenticate via HTTP and escalate privileges without user interaction. Successful exploitation results in complete compromise of the application, granting the attacker full read, write, and administrative control over the system. The vulnerability is easily exploitable and requires only network access and valid credentials; there is no indication of active exploitation in the wild at this time.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed