Impact
A low‑privileged attacker that can reach Oracle HRMS (UK) over HTTP can perform unauthorized updates, inserts, or deletes, read restricted data, and trigger a partial denial of service. The flaw stems from information exposure (CWE‑200), privilege escalation (CWE‑269), and missing authorization controls (CWE‑284) that together grant confidentiality, integrity, and availability damage reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L.
Affected Systems
The affected component is Oracle HRMS (UK) within Oracle E‑Business Suite, specifically supported versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests that the risk of exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog. However, the low attack complexity and requirement for only network access over HTTP mean that a malicious actor can reach the target within a corporate network and exploit the flaw if it remains unpatched.
OpenCVE Enrichment