Impact
A vulnerability in Oracle HRMS (UK) allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical HR data without proper authorization. The flaw can also lead to a partial denial of service for the HRMS (UK) application, compromising availability. The weakness arises from insufficient enforcement of access controls, resulting in integrity and availability impacts.
Affected Systems
Vulnerable systems are Oracle HRMS (UK) components of Oracle E‑Business Suite, specifically the UK Payroll module. Affected supported versions range from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a medium severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation as of the current data. The vulnerability is not listed in CISA KEV. It is likely exploitable by an attacker who can reach the HRMS HTTP endpoint and has minimal local privileges, enabling unauthorized data operations and service disruptions without elevated privileges.
OpenCVE Enrichment