Executive brief
Oracle Hyperion Data Relationship Management is an enterprise data management platform used to organize and maintain critical business data relationships. An unauthenticated attacker can exploit a vulnerability in the access control mechanism to bypass authentication and gain unauthorized access to sensitive data, allowing them to view, modify, or delete critical information without permission. This could expose confidential business intelligence, disrupt data integrity, and compromise the reliability of downstream reporting and analytics systems.
Technical details
The vulnerability is an authentication bypass in the access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An unauthenticated attacker with network access via HTTP can exploit a difficult-to-exploit flaw (high complexity required) to compromise the product. Successful exploitation results in high confidentiality and integrity impact, allowing unauthorized creation, deletion, or modification of critical data and unrestricted access to all DRM-accessible information. No user interaction is required. The CVSS 3.1 score is 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Patch status and detailed root cause information are not yet available.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed