Impact
A flaw in Oracle HRMS (Norway) allows a highly privileged user who can reach the system over HTTP to compromise the application. The weakness is a privilege‑escalation or improper access control issue that can lead to loss of confidentiality, integrity, and availability of payroll data and ultimately to full takeover of the HRMS instance.
Affected Systems
Oracle Corporation’s Oracle HRMS (Norway) component of Oracle E‑Business Suite, specifically the Norway Payroll module, in the supported versions 12.2.8 through 12.2.15 is vulnerable. No other Oracle products or versions are currently listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 denotes a moderate severity, while the EPSS score of less than 1 % and the absence from CISA’s KEV catalog indicate limited momentum in the wild. The attack vector requires network‑exposed HTTP access and accounts with high‑privileges, so the risk is concentrated for environments where privileged users or compromised credentials already exist. If such conditions are met, an attacker can gain complete control over the HRMS service.
OpenCVE Enrichment