Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data integration and governance platform used to manage critical business data relationships and metadata. A vulnerability in its access control mechanisms allows a low-privileged authenticated user to gain unauthorized read, write, and delete access to sensitive data, potentially compromising confidentiality and data integrity across the organization.
Technical details
This is an authorization bypass vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability allows a low-privileged attacker with network access via HTTP and valid credentials to bypass access controls and perform unauthorized create, delete, and modification operations on critical data. The attack requires authentication (PR:L) but no user interaction. Successful exploitation results in unauthorized access to and modification of all accessible data within the DRM system. No patch status is currently known from the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed