Sceawere

Vulnerability Detail

CVE-2026-70895UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion DRM Security Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:47.117Z",
  "pubdate": "2026-08-18T21:17:47.117Z",
  "executiveSummary": "An easily exploitable vulnerability within the Access and security component of Oracle Hyperion Data Relationship Management allows a low-privileged authenticated attacker with logon access to the underlying infrastructure to compromise the application. The vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.25.0.000 and carries a CVSS 3.1 Base Score of 6.5 with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N.\nAlthough the primary security flaw resides within Oracle Hyperion Data Relationship Management, a successful attack exhibits a scope change, which can significantly impact additional co-located or integrated products within the enterprise infrastructure. The primary consequence of successful exploitation is unauthorized or complete access to critical and sensitive data accessible by Oracle Hyperion Data Relationship Management, strictly impacting confidentiality.\nExploitation requires physical or remote interactive logon access to the host infrastructure hosting the vulnerable software, paired with low privileges on the local system. The low attack complexity indicates that once the prerequisite access is obtained, the vulnerability can be leveraged reliably without advanced exploitation techniques.",
  "technicalDetails": "The vulnerability exists within the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The root cause stems from insecure handling of security controls, permissions, or access enforcement within the application architecture, permitting local boundary bypasses.\nThe attack vector is classified as Local (AV:L), meaning the adversary must already possess an authenticated logon session on the underlying operating system or infrastructure where Oracle Hyperion Data Relationship Management is deployed and executes. The attack complexity is low (AC:L), requiring minimal specialized conditions or race conditions to successfully execute the attack vector. Furthermore, user interaction is not required (UI:N).\nThe attacker must possess low privileges (PR:L) within the local execution environment. From an attack flow perspective, an authenticated low-privileged user leverages their local access to interact with vulnerable functions, binaries, configuration files, or insecure inter-process communication channels associated with the Access and security component of Oracle Hyperion Data Relationship Management.\nDue to the scope change (S:C) characteristic of this vulnerability, the security context of the affected component expands beyond its administrative boundary. Consequently, successful exploitation breaches the isolation between Oracle Hyperion Data Relationship Management and other resources or products residing on the same infrastructure, leading to collateral security degradation.\nThe post-exploitation impact is focused heavily on confidentiality (C:H), resulting in unauthorized retrieval, exposure, or complete access to all critical data accessible via Oracle Hyperion Data Relationship Management. Integrity and availability impacts remain unaffected (I:N/A:N)."
}
CVE-2026-70895: Oracle Hyperion DRM Security Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere