Impact
The vulnerability exists in the Oracle HRMS (UK) component of Oracle E-Business Suite, affecting the UK Payroll module. It is an information‑exposure flaw that permits a privileged attacker with network access over HTTP to read a subset of HRMS data. The weakness is classified as a low‑severity confidentiality breach and is hard to exploit, requiring high privilege and network access, but it still allows disclosure of sensitive information.
Affected Systems
Affected systems include Oracle’s HRMS (UK) product line, versions 12.2.3 through 12.2.15, as listed in Oracle’s CPU July 2026 security alert. No other vendors or product versions are identified.
Risk and Exploitability
The CVSS 3.1 Base Score of 2.2 highlights the limited impact, affecting only confidentiality. The EPSS score is below 1 %, indicating that exploitation is unlikely under current threat conditions. The vulnerability is not included in the CISA KEV catalog. The likely attack vector involves a high‑privileged attacker who can reach the HRMS instance via HTTP, and the attacker must have prior privileged access within the environment to succeed.
OpenCVE Enrichment