Impact
A high privileged attacker with network access can exploit a vulnerability by sending HTTP requests, leading to a full takeover of the Oracle HCM Common Architecture component. The flaw is classified as not highly complex and the attack requires network connectivity over HTTP. The CVSS 3.1 base score of 7.2 reflects significant confidentiality, integrity, and availability impacts. The attacker gains full control of the HCM Common Architecture and can use it to affect the broader Oracle E‑Business Suite environment.
Affected Systems
The affected product is Oracle HCM Common Architecture, part of Oracle E‑Business Suite, with vulnerable versions ranging from 12.2.3 through 12.2.15. The vulnerability is present in the Internal Operations component, and any deployment of this architecture within that version range is at risk.
Risk and Exploitability
The CVSS score indicates a high severity and the EPSS value of less than 1% indicates that exploitation cases are expected to be rare at present. However, the vulnerability is not listed in the CISA KEV catalog, implying that no publicly known exploitation has been documented yet. The attack requires network connectivity over HTTP to the target, and the attacker must already have high‑privilege credentials on the system. If such credentials are available, the exploit can be executed with minimal effort, resulting in a takeover of the entire Oracle HCM Common Architecture component.
OpenCVE Enrichment