Impact
This vulnerability is an Insecure Direct Object Reference (IDOR) flaw located in the Employee Compensation View function of Infor Global HR. The IDOR allows an unauthenticated or improperly authorized attacker to construct a special GET request and view the compensation details of any employee within the organization. Because compensation data is highly sensitive, the exploitation of this flaw results in a confidentiality breach, exposing personal financial information applicable to each employee.
Affected Systems
The affected product is Infor Global HR version 11.24.10.01.33. Users running this specific release are at risk; no other vendors or product variants are listed as impacted in the current data.
Risk and Exploitability
With a CVSS score of 7.5 this issue is rated High, reflecting the severity of the confidentiality impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a crafted HTTP GET request to the compensation view endpoint, exploiting the lack of proper authorization checks. In practice, an attacker would need network access to the application and knowledge of valid employee identifiers to benefit from this flaw.
OpenCVE Enrichment