Impact
A flaw in Oracle Human Resources’ Enterprise Command Center component allows a low‑privileged user who can log on to the host operating system to create, delete, or modify critical HR data. The vulnerability gives the attacker unauthorized access to all data that the application normally protects, impacting both confidentiality and integrity. The flaw is classified as a local–access control issue (CWE‑284), exposing the system to changes of information that could be used for fraud, identity theft, or disruption of HR processes.
Affected Systems
Oracle Human Resources, part of Oracle E‑Business Suite, is affected. Supported versions 12.2.14 and 12.2.15 contain the flaw. Users running either of these releases should verify whether their installations include this component and assess exposure.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a medium‑to‑high severity, with high confidentiality and integrity impact. The EPSS score of less than 1% suggests a low probability of imminent widespread exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, because the attack requires only local access and low privilege, any insider or compromised account that can log into the HR server can exercise the flaw. The lack of a user interaction requirement makes it easy to exploit for an attacker in control of the host.
OpenCVE Enrichment