Impact
The vulnerability allows a low‑privileged attacker with network access via HTTP to modify or delete data, read restricted information, and cause a partial denial of service in Oracle HRMS (US). The flaw is in the US Payroll – General module of Oracle E‑Business Suite, affecting versions 12.2.3 through 12.2.15. The impact covers confidentiality, integrity, and availability of HRMS data and processes.
Affected Systems
Oracle Corporation’s HRMS (US) product, versions 12.2.3 through 12.2.15, is affected. The US Payroll – General module in this range exposes an HTTP interface in the U.S. deployment of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS v3.1 base score is 6.3, indicating medium impact on confidentiality, integrity, and availability. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no known active exploits are reported. The likely attack vector is a low‑privileged attacker with network access to the HTTP endpoint; exploitation would involve unauthorized modification, deletion, or read of data and potentially a partial denial of service.
OpenCVE Enrichment