Impact
Oracle HRMS (New Zealand) has a vulnerability that permits a low‑privileged attacker with network access through the HTTP interface to modify, insert or delete certain HR data and read a subset of information. The flaw is reflected in the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) and indicates that confidentiality and integrity are affected. The impact can lead to unauthorized alteration and disclosure of employee data, which may affect operational integrity and regulatory compliance.
Affected Systems
The affected vendor is Oracle Corporation. The product is Oracle HRMS (New Zealand) within the Oracle E‑Business Suite, specifically the New Zealand Payroll component. Vulnerable releases span 12.2.3 through 12.2.15, as identified by the listed CPE.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate risk with low confidentiality and integrity impact and no availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalogue. Because the attack vector is via a network HTTP interface and only requires low privilege, the flaw is relatively easy to exploit once the target is reachable, but it presumes the attacker already has some level of network access to the HRMS environment.
OpenCVE Enrichment