Impact
The vulnerability allows an attacker with low privileges and network access through HTTP to compromise the Oracle HRMS (France) product of Oracle E-Business Suite. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data or the ability to read all data accessible through the HRMS. This issue stems from an improper access control weakness (CWE-284) and compromises confidentiality and integrity.
Affected Systems
Affected versions are Oracle HRMS (France) in Oracle E-Business Suite from 12.2.3 through 12.2.15. No other products are listed.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, with confidentiality and integrity impacts. The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to reach the HRMS over HTTP and possess low‑privilege accounts. Given the high severity and the requirement for network proximity, the overall risk is significant but the likelihood of widespread exploitation remains low.
OpenCVE Enrichment