Impact
Vulnerability in Oracle HRMS (US) allows a low‑privileged attacker who has logged onto the infrastructure where HRMS runs to cause a complete denial of service and to read, insert, update, or delete data that the application normally protects. Based on the description, it is inferred that the vulnerability stems from improper authorization and resource exhaustion, leading to confidentiality, integrity, and availability degradation as reflected by the CVSS vector.
Affected Systems
The affected product is Oracle HRMS (US) component of Oracle E‑Business Suite for versions 12.2.9 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. Successful exploitation requires local access to the host that runs HRMS and the attacker’s ability to interact with the application, making the attack vector local and privilege‑lowering. If these conditions are met, the attacker can repeatedly crash the service and manipulate accessible data.
OpenCVE Enrichment