Executive brief
Oracle Hyperion Data Relationship Management is a enterprise data management system used to manage critical business data across organizations. An unauthenticated attacker can exploit a vulnerability in the SMTP interface to bypass authentication and gain unauthorized access to create, delete, or modify sensitive data, or read all accessible information stored in the system.
Technical details
This is an authentication bypass vulnerability in the Oracle Hyperion Data Relationship Management SMTP interface that allows unauthenticated network attackers to compromise the system. The vulnerability is difficult to exploit and requires specific preconditions via the SMTP protocol. Successful exploitation enables attackers to perform unauthorized data operations including creation, deletion, and modification of critical records, as well as full read access to all data within the system. The vulnerability affects version 11.2.26.0.000; patch availability information was not accessible from the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed