Impact
This weakness, identified as CWE‑200 (Information Exposure), exists in the HRMS (Australia) component of Oracle E‑Business Suite Payroll and allows an attacker with low privileges and network access over HTTP to read data that should remain confidential. The flaw allows unauthorized access to critical payroll information or full visibility into all HRMS (Australia) data. The exploitation does not provide code execution or denial of service, but it does compromise the confidentiality of the data stored or processed by the application.
Affected Systems
Oracle HRMS (Australia), part of Oracle E‑Business Suite, specifically the Payroll module, is affected. Versions 12.2.3 through 12.2.15 are impacted. Attackers only need low‑level credentials and a network connection over HTTP; no special local access is required.
Risk and Exploitability
The CVSS base score is 6.5, reflecting a moderate severity with a high confidentiality impact. The EPSS score is below 1%, indicating that the likelihood of exploitation at present is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP, so any exposed HRMS (Australia) instance that can be reached over the network is a potential target, especially if proper access controls are not enforced.
OpenCVE Enrichment