Impact
Oracle HRMS (UK), part of Oracle E-Business Suite, contains a vulnerability that enables an attacker with low privileges and network access to issue HTTP requests that return confidential application data. The flaw is classed as an information disclosure and authorization bypass weakness, which permits read-only access to all data exposed by the HRMS module without needing valid user credentials. No impact on data integrity or availability is described.
Affected Systems
Affected releases range from 12.2.8 through 12.2.15. These versions include the Internal Operations component of Oracle HRMS (UK). Any installation of these releases that listens for HTTP traffic is vulnerable, regardless of operating system or additional Oracle components deployed alongside.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, with high attack complexity and low privileges required, and no user interaction. The EPSS score of less than 1 % suggests a very low probability of public exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The descriptive note that the scope changes implies that a successful compromise may affect ancillary Oracle products, expanding the overall attack surface. The most likely attack vector is remote over the network via HTTP, as indicated by the vector string AV:N.
OpenCVE Enrichment