Executive brief
Oracle Hyperion Data Relationship Management is an enterprise platform used to manage complex data relationships and access control within financial and business systems. An unauthenticated remote vulnerability allows attackers to bypass authentication and gain complete access to sensitive data stored in the system without providing valid credentials, potentially exposing confidential business and financial information.
Technical details
This is an authentication bypass vulnerability in Oracle Hyperion Data Relationship Management's access and security component. The vulnerability is easily exploitable and requires only network access via HTTP, with no authentication or user interaction needed. An unauthenticated attacker can leverage this to gain unauthorized access to all data managed by the system. The affected version is 11.2.25.0.000. Oracle has released security updates to address this issue; patches are available through their Critical Patch Update program.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed