Impact
The flaw in Oracle Human Resources is an instance of CWE‑284 Improper Access Control. A high privileged attacker who has network access via HTTP can invoke the Data Removal Tool and override normal security controls, leading to a full takeover of the application. Successful exploitation compromises confidentiality, integrity, and availability, as reflected by the CVSS 3.1 score of 7.2.
Affected Systems
Oracle Human Resources within Oracle E‑Business Suite is affected, specifically versions 12.2.3 through 12.2.15. The vulnerability resides in the Data Removal Tool component and requires the tool to be running and reachable over the network.
Risk and Exploitability
The vulnerability is rated easily exploitable with an AV:N/AC:L attack vector over HTTP. It demands a high privileged attacker and provides no user interaction. The CVSS base score of 7.2 indicates moderate‑high severity, but the EPSS score is under 1% which suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the potential for complete system takeover renders it a serious risk for exposed systems.
OpenCVE Enrichment