Impact
The Oracle HRMS ( Hong Kong) product includes a flaw that lets a low‑privileged attacker with network access over HTTP alter, delete, insert, or read data that should be protected. The vulnerability directly affects the confidentiality and integrity of HRMS data without impacting availability. The weakness is an access‑control issue that lets unauthorized users perform privileged operations that they should not be allowed to execute.
Affected Systems
Affected versions are Oracle HRMS ( Hong Kong) 12.2.13 through 12.2.15, part of Oracle E‑Business Suite’s Hong Kong Payroll component. This applies to installations of the Oracle HRMS ( Hong Kong) product that have not been patched to a newer release.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate risk; the system could suffer non‑critical confidentiality and integrity breaches. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be over the HTTP interface, reachable from the network and feasible for an attacker with low privileges who can reach the HRMS service.
OpenCVE Enrichment