Sceawere
Vulnerability Detail
CVE-2026-70897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion DRM Access Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Data Relationship Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-18T21:17:47.357Z",
"pubdate": "2026-08-18T21:17:47.357Z",
"executiveSummary": "An unauthenticated security vulnerability affects the Access and security component of the Oracle Hyperion Data Relationship Management product, specifically version 11.2.25.0.000. This remotely exploitable flaw allows network-based adversaries to compromise the targeted system via the HTTPS protocol without requiring any prior authentication or user interaction. Successful exploitation of this vulnerability severely compromises both data confidentiality and integrity. Specifically, attackers can achieve unauthorized access to critical data or complete access to all data accessible by Oracle Hyperion Data Relationship Management. Furthermore, the vulnerability permits unauthorized insertion, updating, or deletion of specific subsets of accessible data within the application. Given the high CVSS 3.1 base score of 8.2, organizations utilizing the affected version face substantial risk regarding unauthorized data exposure and state manipulation. The attack vector is strictly network-based with low attack complexity, requiring no privileges, which significantly lowers the barrier for malicious actors to execute successful attacks against exposed endpoints.",
"technicalDetails": "The vulnerability resides within the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. From an architectural perspective, the flaw exposes critical internal access control mechanisms or authentication boundaries over the HTTPS protocol, permitting unauthenticated entities to bypass intended security controls. The exploitation method relies on network accessibility where an attacker crafts and transmits malicious HTTPS requests directly to the vulnerable application endpoints without supplying valid session credentials or authentication tokens. Because the application fails to adequately validate the identity and authorization state of the requestor prior to processing sensitive data transactions, the security boundary is effectively nullified. The step-by-step attack flow begins with the malicious actor identifying a network-exposed instance of Oracle Hyperion Data Relationship Management running the vulnerable 11.2.25.0.000 version. The attacker then initiates HTTPS communication with the target server, bypassing authentication filters due to improper handling of security contexts within the Access and security component. Upon successful transmission of the crafted payload, the application processes the request with elevated privileges or default trust assumptions. Post-exploitation impact manifests as a severe breach of confidentiality, granting the adversary read access to critical or all accessible enterprise master data repositories. Additionally, the vulnerability allows the attacker to execute unauthorized data manipulation operations, including insert, update, and delete actions against supported data structures within Oracle Hyperion Data Relationship Management. The technical metrics defining this vector include a network attack vector (AV:N), low attack complexity (AC:L), zero required privileges (PR:N), and no user interaction (UI:N) under a unchanged scope (S:U), resulting in high confidentiality impact (C:H) and low integrity impact (I:H/L), with no availability disruption (A:N)."
}