Sceawere

Vulnerability Detail

CVE-2026-70893UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion DRM SQL Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:46.060Z",
  "pubdate": "2026-08-18T21:17:46.060Z",
  "executiveSummary": "An input-based vulnerability affecting the Oracle Hyperion Data Relationship Management product of Oracle Hyperion, specifically within the Access and security component, presents significant security risks to enterprise deployments.\nThe vulnerability affects version 11.2.25.0.000 and can be exploited by a low-privileged attacker who has network access via SQL.\nSuccessful exploitation of this flaw is classified as difficult, but it introduces a scope change that allows attacks to significantly impact additional secondary products beyond the primary vulnerable application.\nThe security implications include unauthorized creation, deletion, or modification of critical data, alongside complete unauthorized access to all accessible Oracle Hyperion Data Relationship Management data.\nThe severity of the issue is reflected in a CVSS 3.1 Base Score of 8.2, driven by high impacts on both confidentiality and integrity, while availability remains unaffected.\nOrganizations utilizing the affected version must implement rigorous access controls and monitor SQL-based network interactions to mitigate unauthorized data manipulation and cross-product exposure risks.",
  "technicalDetails": "The vulnerability resides within the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000.\nThe root cause stems from insufficient validation and handling of SQL-based interactions processed by the application, allowing an authenticated entity with low privileges to abuse database-level execution pathways.\nExploitation requires network access coupled with the ability to interact with the system via SQL protocols, categorized under an attack vector of AV:N and a high attack complexity rating (AC:H).\nAlthough the attacker requires low privileges (PR:L) and no user interaction (UI:N), the complexity is elevated due to the precise conditions required to leverage the SQL attack surface successfully.\nThe attack flow begins with the low-privileged attacker establishing network connectivity to the vulnerable database or application interface supporting SQL access.\nBy submitting crafted SQL payloads through the exposed database interaction layer, the attacker bypasses intended security boundaries enforced by the Access and security component.\nBecause the vulnerability exhibits a scope change (S:C), successful execution is not restricted to the local context of Oracle Hyperion Data Relationship Management; rather, it extends privileges and impacts additional collateral products integrated within the environment.\nPost-exploitation impacts involve complete compromise of data integrity and confidentiality.\nThe malicious payload enables unauthorized actors to read, create, modify, or delete critical enterprise data housed within Oracle Hyperion Data Relationship Management and potentially linked secondary systems.\nThe CVSS 3.1 vector is formally defined as (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N), confirming the exclusion of availability disruption while highlighting severe data exposure and manipulation risks."
}
CVE-2026-70893: Oracle Hyperion DRM SQL Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere