Impact
An unauthenticated attacker can use a direct HTTP connection to exploit a flaw in the Oracle iRecruitment component of Oracle E‑Business Suite, allowing unauthorized access to critical data or even all data exposed by the application. The vulnerability lacks a required authentication step and relies on network access, resulting in a complete compromise of confidentiality for the affected system.
Affected Systems
The affected vendor is Oracle Corporation and the product is Oracle iRecruitment. Versions from 12.2.3 through 12.2.15 are impacted, as noted in the official Oracle CPU Jul 2026 advisory. All installations of iRecruitment within that version range that expose the Internal Operations component over HTTP are susceptible.
Risk and Exploitability
The CVSS v3.1 base score is 7.5, indicating a high‑severity flaw that primarily impacts confidentiality. The EPSS score is below 1 %, suggesting a low probability of exploitation. The vulnerability is network‑based via HTTP, with no authentication required, and is described as "easily exploitable". The potential for full data exposure means organizations should treat this as a high‑priority risk, especially if the application is reachable from outside the internal network.
OpenCVE Enrichment