Executive brief
Oracle Hyperion Data Relationship Management is a financial planning and data management tool used by enterprises to consolidate and analyze business data. A vulnerability in access controls allows a low-privileged user with local system access to gain full control of the system, potentially compromising sensitive financial and operational data across multiple interconnected systems.
Technical details
This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management. The vulnerability requires local access (AV:L) and low-level privileges but is difficult to exploit (AC:H). An authenticated attacker with logon access to the infrastructure can escalate privileges to compromise the entire system. The vulnerability has a scope change (S:C), meaning successful exploitation can impact other products and systems connected to the Hyperion environment. The attack requires no user interaction (UI:N) and results in complete compromise of confidentiality, integrity, and availability.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed