Impact
The vulnerability exists in Oracle HRMS UK Payroll, a component of Oracle E‑Business Suite. An attacker who has low privileges but can reach the application over HTTP can exploit the flaw to compromise the system, eventually taking full control of Oracle HRMS (UK). The 8.8 shows high impacts on confidentiality, integrity and availability, indicating that a successful exploitation can lead to total loss of those assets. The description does not specify the exact exploitation mechanism, but it states that the vulnerability is easily exploitable and results in system takeover.
Affected Systems
Affected are Oracle Corporation’s Oracle HRMS UK Payroll component of Oracle E‑Business Suite. The issue applies to supported versions 12.2.8 through 12.2.15. Administr these specific version numbers that are deployed in their environment. Network access is required via HTTP, so the attack can be launched from any source that can reach the HRMS web services.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1%, suggesting that exploitation remains rare but not impossible. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a crafted HTTP request that bypasses proper authentication checks, allowing privilege escalation to system level. No additional exploitation prerequisites beyond network access to the HRMS HTTP interface are mentioned, so any user with low privileges and network reach could potentially exploit the flaw. This inference is drawn from the statement that a low‑privileged attacker with network access via HTTP can compromise the system.
OpenCVE Enrichment