Impact
The flaw in Oracle HRMS (France) enables a low‑privileged user who can reach the application over HTTP to create, delete, or modify critical data and to obtain unauthorized access to all HRMS data. The issue is an improper access control weakness that impacts both confidentiality and integrity.
Affected Systems
Oracle Corporation’s Oracle HRMS (France) component of the Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. These versions remain supported by Oracle as noted in the vendor advisory.
Risk and Exploitability
The vulnerability is easily exploitable, requiring only an HTTP connection and a low‑privileged account. With a CVSS 3.1 base score of 8.1, the risk to data is significant. The EPSS score of less than 1% indicates that the flaw is not yet commonly seen in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is a network‑accessible HTTP endpoint, making the flaw attractive to threat actors who can reach the HRMS interface.
OpenCVE Enrichment