Impact
Oracle iRecruitment contains a weakness that permits a high‑privileged attacker with network access to its HTTP interface to fully take over the application. The flaw can be leveraged to alter data and control recruitment processes, leading to confidentiality, integrity and availability violations.
Affected Systems
The affected product is Oracle iRecruitment, a component of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS rating of 7.2 indicates a moderate‑to‑high severity vulnerability with full impact on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The attack requires network reach to the HTTP interface and that the attacker is already privileged or has compromised credentials. Even though the vulnerability is not listed in CISA’s KEV catalog, successful exploitation would grant the attacker full control of the application, presenting a significant risk to affected organizations.
OpenCVE Enrichment