Impact
The flaw in Oracle Public Sector Human Resources allows a low‑privileged attacker with network access via HTTP to create, delete or modify critical records. The vulnerability can also be leveraged to obtain unauthorized access to all data exposed by the application, leading to significant confidentiality and integrity violations.
Affected Systems
Oracle Public Sector Human Resources, a component of Oracle E‑Business Suite, is affected. Supported releases from 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity. The EPSS score is below 1%, suggesting limited current exploitation likelihood. The flaw is not listed in the CISA KEV catalog. Exploitation requires only HTTP network reachability and low privilege, meaning that attackers with basic network access could abuse the vulnerability without higher rights.
OpenCVE Enrichment