Impact
The vulnerability allows a low‑privileged attacker who has logged onto the infrastructure where Oracle HRMS (US) runs to compromise the HRMS instance. Successful exploitation can lead to a complete takeover of the application, resulting in loss of confidentiality, integrity, and availability of HRMS data and services. The flaw is specifically difficult to exploit, but when it is, it gives the attacker full control over the HRMS environment.
Affected Systems
Oracle Corporation’s Oracle HRMS (US) component of Oracle E-Business Suite. Supported versions affected are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 7.0 reflects high impact to confidentiality, integrity, and availability. The EPSS score is less than 1%, indicating a low probability of exploitation at this time. This vulnerability is not listed in the CISA KEV catalog. The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) implies a local attack that requires prior logon to the system hosting HRMS. The attacker must have low privileges on the underlying infrastructure; once the flaw is leveraged, they gain full control of the HRMS application.
OpenCVE Enrichment