Impact
The vulnerability resides in the install and upgrade component of Oracle iRecruitment. An attacker who possesses only low privileges and network connectivity to the HTTP interface can exploit this flaw, yielding unauthorized insert, update, or delete operations on Oracle iRecruitment data, and may also read a subset of that data. The impact compromises confidentiality and integrity but does not affect availability.
Affected Systems
Oracle Corporation’s Oracle iRecruitment product, versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
The CVSS v3.1 score of 5.4 represents moderate severity, with an EPSS score of less than 1% indicating that exploit attempts are rare, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to target the private‑network HTTP endpoint; no elevated privileges or user interaction are required.
OpenCVE Enrichment