Impact
The Oracle US Federal Human Resources component of Oracle E-Business Suite is vulnerable to a low-privileged, network-based attack that allows an attacker to create, delete, or modify critical data. The impact is significant, as the attacker can compromise confidentiality and integrity of all data accessible through the application, potentially gaining complete access to the database. The weakness appears to be an access control flaw that permits privileged actions without proper authorization checks.
Affected Systems
Vendors affected: Oracle Corporation. Products impacted are Oracle US Federal Human Resources, version range 12.2.3 to 12.2.15 in the Internal Operations component. No other vendors or topographical product names are listed.
Risk and Exploitability
The base CVSS 3.1 score of 8.1 indicates a high severity issue with high confidentiality and integrity impact. The EPSS score of less than 1% suggests low current exploitation likelihood, but the vulnerability is easily exploitable for network users with HTTP access. The product is not listed in the CISA KEV catalog, so there is no evidence of widespread exploitation yet. The likely attack vector is a standard HTTP request to a privileged endpoint; the vulnerability can be leveraged by an attacker who is not authenticated or holds a low privileged account within the network. The overall risk is moderate to high for organizations that expose the application to external or untrusted traffic, and it warrants timely remediation.
OpenCVE Enrichment