Impact
The vulnerability resides in the Regression Testing component of Oracle Public Sector Human Resources and represents an authorization weakness (CWE-284). It allows an attacker with low‑level privileges to interact over HTTP and perform unauthorized insert, update, or delete operations, as well as read selected data. This grants the attacker both integrity and confidentiality impact as reflected in the CVSS 5.4 score.
Affected Systems
Oracle Public Sector Human Resources versions 12.2.3 through 12.2.15 are affected. The product is offered by Oracle Corporation as part of its E‑Business Suite for public‑sector human‑resources applications.
Risk and Exploitability
The CVSS Base Score of 5.4 indicates a moderate severity, with the EPSS score below 1% and no listing in the CISA KEV catalog. The likely attack vector is a low‑privileged user that can reach the application via HTTP on the network. Successful exploitation requires only network access and results in unauthorized data modification or exfiltration, making it a potentially useful tool for a threat actor with modest capabilities.
OpenCVE Enrichment