Impact
This vulnerability in the Norway Payroll component of Oracle HRMS allows a high‑privileged attacker with network access via HTTP to update, insert, or delete restricted payroll data and read a subset of data that should be protected. The flaw stemmed from insufficient access control for privileged operations, leading to confidentiality and integrity impacts as reflected by a CVSS score of 3.8.
Affected Systems
Oracle Corporation’s Oracle HRMS (Norway) payroll component, version numbers 12.2.3 through 12.2.15 inclusive, is affected. These releases are part of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 Base Score 3.8 indicates low severity, with low confidentiality and integrity impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. Because the vulnerability is easily exploitable over HTTP, a high‑privileged remote attacker could gain unauthorized data modification or disclosure, yet the risk remains relatively contained. Oracle has not listed this issue in the CISA KEV catalog.
OpenCVE Enrichment