Impact
Oracle Human Resources is vulnerable to a flaw in its Data Removal Tool that allows a high‑privileged attacker who can reach the application over HTTP to compromise the entire system. The vulnerability is exploited by manipulating the tool’s input or execution flow, providing the attacker with the ability to read, modify, or delete sensitive data, and ultimately leading to full takeover. The flaw represents an Improper Access Control (CWE‑284). The supported versions in scope are 12.2.3 through 12.2.15.
Affected Systems
Oracle Human Resources products from Oracle Corporation, specifically versions 12.2.3 through 12.2.15, are affected by this vulnerability. Customers running these releases should verify that their installations are deployed with the Data Removal Tool component and assess whether the version falls within the impacted range.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% shows unlikely but not impossible. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers need network access to the HTTP interface and possession of sufficient privileges to use the Data Removal Tool. Successful attacks would give complete control over the Oracle Human Resources application.
OpenCVE Enrichment