Impact
A remote attacker with low privileges who can reach Oracle iRecruitment over HTTP can create, delete or modify critical data, leading to serious breaches of confidentiality and integrity. The vulnerability forces the system to accept privileged operations from users who should not have them, while the availability of iRecruitment services remains unchanged.
Affected Systems
Oracle Corporation’s Oracle iRecruitment component of Oracle E‑Business Suite, with affected versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS‑3.1 base score of 8.1 indicates a high impact on confidentiality and integrity. An EPSS score of <1% suggests that exploitation is unlikely but still possible, and the vulnerability is not listed in CISA’s KEV catalog, so no known public exploits exist. An attacker would need low‑privilege credentials and network access via HTTP to craft requests that bypass the component’s access controls.
OpenCVE Enrichment