CVE-2019-2927 is a difficult-to-exploit vulnerability in Oracle Hyperion Data Relationship Management (version 11.1.2.4), specifically impacting its Access and Security component. A high-privileged attacker with network access via HTTP could compromise the system, requiring human interaction from a non-attacker. Successful exploitation leads to a complete takeover of Hyperion Data Relationship Management, with high impacts on confidentiality, integrity, and availability, resulting in a CVSS 3.0 Base Score of 6.4 (Medium). There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2.4CPE matchmatch criteria | cpe:2.3:a:oracle:hyperion_data_relationship_management:11.1.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.