Impact
A defect in Oracle HRMS (UK) allows a low‑privileged attacker who can reach the application over HTTP to alter data—perform updates, inserts, or deletes—and to read data that should be protected. This is a CWE‑284: Improper Authorization vulnerability. The flaw does not affect availability but can compromise the confidentiality and integrity of HRMS data.
Affected Systems
Oracle HRMS (UK) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity with low confidentiality and integrity impact. The EPSS score of fewer than 1% shows the likelihood of exploitation is low. Oracle HRMS (UK) is not listed in the CISA KEV catalog. The vulnerability can be exploited by any attacker who has network access to the HRMS HTTP interface with no elevated privileges, typically by sending crafted HTTP requests to the payroll component.
OpenCVE Enrichment