Executive brief
Oracle Hyperion Data Relationship Management is a data management and reporting product used by enterprises to model and manage complex business data relationships. An unauthenticated attacker can bypass security controls over the network to read, create, modify, or delete critical business data and configuration information without authorization, potentially affecting downstream business intelligence and operational systems.
Technical details
This is an authentication bypass or authorization flaw in the access control component of Oracle Hyperion Data Relationship Management affecting version 11.2.25.0.000. The vulnerability is accessible to unauthenticated attackers via HTTP (network-reachable), though it is difficult to exploit, suggesting non-trivial preconditions or complexity. Successful exploitation results in unauthorized access to create, modify, delete, or read critical data—indicating both integrity and confidentiality impacts across the product. The scope change designation suggests potential lateral impact to connected systems. No patch availability information is currently provided in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed