Executive brief
Oracle Hyperion Data Relationship Management is a data governance and relationship management platform used by enterprises to manage critical data structures and access controls. This vulnerability allows unauthenticated attackers to read, create, delete, or modify sensitive data through the SOAP interface without providing any credentials, potentially exposing or corrupting entire datasets and compromising the integrity of the organization's data governance.
Technical details
This is an authentication bypass vulnerability in the SOAP interface of Oracle Hyperion Data Relationship Management. An unauthenticated attacker with network access can exploit this flaw to gain unauthorized access to the application's data manipulation functions. The vulnerability allows attackers to perform create, read, update, and delete operations on critical data without authentication. No user interaction or special privileges are required, and the vulnerability affects version 11.2.25.0.000. The attack is trivial to exploit due to low attack complexity and the network-accessible nature of the SOAP endpoint.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed