Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management and integration platform used to consolidate and govern critical business information across organizations. An unauthenticated network attacker can exploit an access control vulnerability to completely compromise the system, potentially leading to unauthorized access to sensitive financial and operational data, data manipulation, and service disruption across dependent enterprise systems.
Technical details
An easily exploitable authentication bypass vulnerability exists in Oracle Hyperion Data Relationship Management version 11.2.25.0.000 in the access and security component. The vulnerability allows an unauthenticated attacker with network access via TCP to bypass authentication controls without requiring user interaction or additional complexity. Successful exploitation results in complete system takeover with high confidentiality, integrity, and availability impact. The scope is changed, meaning attacks on Hyperion DRM can significantly compromise additional connected products and systems. No patch information is currently available in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed