Impact
The flaw in Oracle Self‑Service Human Resources is an access control weakness (CWE‑284) that allows a low‑privileged attacker who can reach the application over HTTP to perform unauthorized update, insert, or delete operations, and read a subset of HR data. Successful exploitation results in loss of data integrity for HR records and authorized disclosure of confidential personnel information. The vulnerability is limited to the internal Operations component of Oracle E‑Business Suite and does not provide code execution or denial‑of‑service capabilities.
Affected Systems
Oracle Self‑Service Human Resources component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any installation of these releases that exposes the application to the HTTP interface over a network is vulnerable. The exposure can include public‑facing or internal LAN nodes reachable by an attacker with low network privileges.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity. The EPSS score of less than 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. Exploitation requires only network connectivity to the exposed HTTP service and does not require elevated privileges or authentication; a low‑privileged user account or unauthenticated access via the HTTP interface is sufficient. No remote code execution is possible, but the ability to modify or read HR data can have significant operational impact.
OpenCVE Enrichment