Executive brief
Oracle Hyperion Data Relationship Management is a business intelligence and data governance tool used to manage enterprise data structures. A vulnerability allows an unauthenticated attacker to perform unauthorized modifications to critical data or cause service degradation, but requires tricking an authorized user into clicking a malicious link or visiting a crafted webpage. This could result in data corruption, data loss, or temporary system unavailability.
Technical details
This is a cross-site request forgery (CSRF) or social engineering vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management 11.2.26.0.000. The vulnerability is easily exploitable via HTTPS (network-accessible) but requires user interaction (UI:R), specifically requiring an authorized person to be socially engineered or tricked into performing an action. An unauthenticated attacker can leverage this to achieve unauthorized creation, deletion, or modification of data, as well as partial denial of service. The vulnerability affects data integrity and availability. Patching information is not detailed in the advisory.
Affected products
- Oracle Hyperion Data Relationship Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed