Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management platform used to maintain critical data relationships and hierarchies across organizations. A vulnerability in the Access and security component allows an unauthenticated attacker to gain unauthorized access to sensitive data over the network without authentication, potentially exposing confidential business information and analytics.
Technical details
An easily exploitable authentication bypass vulnerability exists in Oracle Hyperion Data Relationship Management version 11.2.25.0.000, located in the Access and security component. The flaw allows unauthenticated attackers with network access via HTTP to bypass authentication controls. An attacker can exploit this vulnerability remotely without requiring valid credentials or user interaction to gain unauthorized read access to critical and sensitive data managed by the product. The vulnerability impacts confidentiality only, with no impact on data integrity or availability. Patch availability status is not detailed in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed