Impact
Oracle HRMS (Ireland) is affected by a vulnerability that permits an attacker with high privileges and network access through HTTP to read a limited portion of the system’s data. The flaw has a low severity rating of 2.2 on the CVSS 3.1 scale, indicating a modest risk to confidentiality only, with no impact on integrity or availability.
Affected Systems
Affected are Oracle E-Business Suite HRMS (Ireland) versions ranging from 12.2.3 to 12.2.15, as listed by Oracle as supported versions.
Risk and Exploitability
Exploitation is considered difficult and requires a network attacker who already holds high privileges within the environment. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or no widespread exploitation activity recorded to date. The CVSS score of 2.2 indicates a low severity and minimal confidentiality impact, reducing the urgency compared to higher‑severity flaws, but the presence of any unauthorized data access still warrants prompt review and mitigation.
OpenCVE Enrichment