Executive brief
Oracle Hyperion Data Relationship Management is a financial planning and consolidation tool used by enterprises to manage complex data hierarchies. A vulnerability in its access control mechanisms allows an authenticated user with low-level privileges to gain full control over the system, potentially compromising confidential financial data, preventing legitimate business operations, and damaging organizational reputation.
Technical details
This is a privilege escalation vulnerability in the access and security component of Oracle Hyperion Data Relationship Management (version 11.2.25.0.000). The vulnerability is network-accessible via HTTP and requires authentication from a low-privileged user, but no user interaction. Successful exploitation allows an attacker to gain administrative control over the application, resulting in complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 Base Score of 8.8 reflects the high severity with network attack vector, low attack complexity, and low privileges required. Patch availability is not confirmed in the advisory text.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed