Sceawere

Vulnerability Detail

CVE-2026-70901UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion DRM Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Data Relationship Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:47.820Z",
  "pubdate": "2026-08-18T21:17:47.820Z",
  "executiveSummary": "A security vulnerability has been identified within the Access and security component of the Oracle Hyperion Data Relationship Management product, specifically affecting version 11.2.25.0.000. This vulnerability is classified as easily exploitable, allowing an unauthenticated remote attacker with network access via the HTTP protocol to compromise the integrity and confidentiality of the targeted system. Successful exploitation of this flaw does not require direct prior access or authentication, but it does mandate human interaction from a victim other than the attacker, such as tricking a legitimate user into interacting with a malicious link or crafted request.\nThe successful exploitation of this vulnerability can lead to severe security implications, yielding unauthorized creation, deletion, and modification capabilities regarding critical data, alongside comprehensive unauthorized access to all accessible data within Oracle Hyperion Data Relationship Management. The severity of this flaw is underscored by a CVSS 3.1 Base Score of 8.1, reflecting high impacts on both confidentiality and integrity with no direct impact on system availability. Given the high-privilege data managed by enterprise master data management solutions, this exposure presents significant operational and compliance risks, necessitating prompt defensive prioritization.",
  "technicalDetails": "The vulnerability resides within the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. The attack surface is exposed over the network via the HTTP protocol, allowing remote threat actors to interact with application endpoints without requiring prior authentication or low-level system privileges. According to the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), the vulnerability exhibits a low attack complexity and requires user interaction, pointing toward client-side attack vectors such as Cross-Site Request Forgery (CSRF) or similar state-changing injection vectors where an authenticated victim's session is leveraged maliciously.\nThe attack flow typically proceeds in a structured sequence. Initially, an unauthenticated attacker crafts a malicious HTTP request or payload designed to interact with the vulnerable Access and security mechanisms of Oracle Hyperion Data Relationship Management. Because direct automated execution may be restricted or require contextual session state, the attacker employs social engineering or malicious content delivery mechanisms to induce human interaction from a valid, authenticated user. Once the victim interacts with the malicious trigger while maintaining an active session, the application processes the request under the security context of the victim.\nUpon successful execution of the attack flow, the underlying logic flaw or inadequate request validation allows the attacker to bypass intended security controls. This leads directly to unauthorized post-exploitation consequences, including the reading of highly sensitive master data, as well as the unauthorized creation, modification, or deletion of critical records within the Oracle Hyperion Data Relationship Management database. The scope remains unchanged (S:U), indicating that the vulnerability impacts solely the security context of the vulnerable application component without directly compounding into underlying host operating system compromises via this specific vector."
}
CVE-2026-70901: Oracle Hyperion DRM Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere