Impact
The vulnerability in Oracle HRMS (US) allows a low‑privileged attacker with network access via HTTP to exploit a defect that is difficult to trigger. Successful exploitation results in unauthorized reading of a subset of the HRMS data and the ability to cause a partial denial of service for the HRMS (US) component. The impact is limited to confidentiality and availability, reflected in a CVSS 3.1 base score of 4.2.
Affected Systems
Oracle Corporation’s Oracle HRMS (US) component “Internal Operations,” affecting all supported releases from version 12.2.3 through 12.2.15. Network access to the HTTP interface of this product is required to reach the vulnerable code.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity level. EPSS is reported as < 1 %, meaning that the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a HTTP requests to the HRMS (US) service. Successful exploitation requires the attacker to hit the specific vulnerable path and is mitigated by proper access control and network segmentation.
OpenCVE Enrichment