Impact
A privilege‑escalation flaw classified as CWE‑269 combined with an access‑control weakness CWE‑284 allows a low‑privileged user who can reach Oracle HRMS (UK) over HTTPS to create, delete, or modify critical HR data, thereby subverting confidentiality and integrity. Successful exploitation can grant the attacker unrestricted access to all data exposed through the platform and, due to a scope change, may also affect other Oracle products that interact with HRMS.
Affected Systems
Oracle HRMS (UK) in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. The flaw resides in the HRMS (UK) component, but the scope change indicates a potential impact on additional Oracle applications that rely on HRMS data.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.2 places this issue in the high‑severity range, while the EPSS score of <1% suggests a low likelihood of current exploitation. It is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTPS and requires an account with low privileges; these characteristics combine to produce a high potential impact but a moderate overall risk given the low exploitation probability.
OpenCVE Enrichment