Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data modeling and relationship platform used to manage critical business data hierarchies and metadata. A SQL injection vulnerability in the access control component allows authenticated attackers to read, modify, or delete sensitive data across the application, potentially affecting multiple connected systems and causing significant data loss or unauthorized disclosure.
Technical details
This is a SQL injection vulnerability in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The vulnerability requires network access and low-level user privileges, with high attack complexity. An authenticated attacker can inject malicious SQL to bypass access controls, leading to unauthorized creation, deletion, or modification of critical data and complete unauthorized access to all accessible data. The scope is marked as changed, indicating potential impact to other connected products and systems. A patch is available via Oracle's critical security update.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed