Impact
The vulnerability permits a low‑privileged attacker with network access via HTTP to gain unauthorized control over Oracle HRMS (UK). Successful exploitation can result in the attacker creating, deleting, or modifying critical payroll data, or accessing sensitive data beyond their authorized scope. The impact is significant to confidentiality and integrity as the CVSS 3.1 score is 8.1 with high C and I impacts.
Affected Systems
Affected only the Oracle HRMS (UK) component of Oracle E‑Business Suite. Versions 12.2.9 through 12.2.15 are susceptible. No other Oracle E‑Business Suite components are known to be impacted.
Risk and Exploitability
The CVSS score of 8.1 reflects a high‑severity vulnerability. The EPSS score is less than 1 %, indicating a low probability of widespread exploitation at the time of analysis, and the weakness does not appear in the CISA KEV catalog. However, the attack vector is a normal network path (HTTP) and the attacker only needs to be a low‑privileged user or compromised internal account, making the threat real for organizations that expose HRMS to network traffic without strict controls.
OpenCVE Enrichment