Impact
A vulnerability exists in the Enterprise Command Center component of Oracle Human Resources within Oracle E‑Business Suite. The flaw is an Access Control weakness (CWE‑284) that can be leveraged by a low‑privileged attacker with network connectivity via HTTP. Successful exploitation enables the attacker to create, delete, or modify data as well as to read all data accessible by Oracle Human Resources, thus compromising both confidentiality and integrity of business information.
Affected Systems
Oracle Corporation – Oracle Human Resources 12.2.14 through 12.2.15 are affected. These versions of the product include the Enterprise Command Center component that is vulnerable.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 8.1, indicating high severity. The EPSS score is below 1 %, meaning exploit probability is low but non‑zero. This vulnerability is not listed in the CISA KEV catalog. The attack path requires network access to the HTTP interface, and the attacker needs only low privileges to mount the attack, making it relatively easy to exploit in a compromised or poorly secured environment.
OpenCVE Enrichment