Executive brief
Oracle Hyperion Data Relationship Management is a data governance and reporting solution used by enterprises to manage financial and operational data relationships. An authenticated network attacker can exploit a flaw in the access control mechanism to gain unauthorized access to, create, delete, or modify critical business data, potentially impacting confidentiality and integrity of sensitive information across the organization.
Technical details
This vulnerability exists in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. It is an authorization bypass flaw that allows a low-privileged attacker with network access via HTTP to circumvent access controls. While exploitation is difficult (high complexity), an authenticated attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible data in the system. The scope changes, meaning the vulnerability may impact other Oracle Hyperion products beyond DRM. A patch or security update from Oracle is required to remediate this issue.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed