Executive brief
Oracle Hyperion Data Relationship Management is a business intelligence and financial reporting platform used by enterprises to manage complex data relationships. A security vulnerability in its access controls allows an attacker with low-level credentials and network access to fully compromise the system, potentially gaining unauthorized access to sensitive financial and operational data across the organization.
Technical details
This is a difficult-to-exploit access and security vulnerability in the access control mechanisms of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability requires a low-privileged authenticated user with network access via HTTP and involves conditions that complicate exploitation (AC:H). A successful exploit enables an attacker to achieve complete compromise (confidentiality, integrity, and availability impacts), with scope change indicating potential for lateral movement to additional Oracle products. No patch information is provided in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed