Impact
An information‑exposure flaw resides in the Manager Self‑Service component of Oracle Self‑Service Human Resources, classified as CWE‑200. The weakness permits a low‑privilege attacker who can reach the HTTP interface to read data that should not be exposed to that user, potentially providing full access to all data available through the system. The CVSS 3.1 base score of 6.5 reflects a high impact on confidentiality while integrity and availability remain unaffected.
Affected Systems
The vulnerability affects Oracle Self‑Service Human Resources of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, when the Manager Self‑Service feature is deployed. Administrators should verify whether their installations fall within this version range and include the affected component.
Risk and Exploitability
Although the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, the attack can be executed over the network via HTTP and only requires low‑privilege credentials. This combination of a network‑based exploitation path and minimal privilege requirement raises the risk of confidential data exposure for any system that permits HTTP access to the Manager Self‑Service endpoint, making confidentiality the primary concern.
OpenCVE Enrichment