Impact
An attacker who gains network access over HTTP can exploit a flaw in the French HR Payroll component of Oracle HRMS (France), allowing unauthorized update, insert or delete operations on data normally protected by access controls and the unauthorized reading of a restricted subset of data. The vulnerability results in a loss of confidentiality and integrity of payroll and personnel records, although availability is not affected. The weakness aligns with CWE‑284, which denotes authorization flaws that permit resource access beyond the intended scope.
Affected Systems
Oracle HRMS (France), part of Oracle E‑Business Suite, is affected in all supported releases from version 12.2.3 through 12.2.15 inclusive. Users operating within this version range should confirm their exact sub‑release and refer to Oracle’s July 2026 CPU advisory for patch details.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates a moderate level of risk, with relatively low confidentiality and integrity impacts but no availability consequences. The vulnerability is easily exploitable: a low‑privileged account that can reach the HRMS instance via HTTP can perform the exploit without requiring user interaction. However, the EPSS score of less than 1% suggests that, at this time, the exploitation probability is very low, and the issue is not presently catalogued in CISA’s KEV list. The likely attack vector is remote over HTTP, requiring only network connectivity to the HRMS endpoint and a non‑privileged account.
OpenCVE Enrichment