Impact
This vulnerability allows an attacker with high privileges and network access via HTTP to compromise Oracle HRMS (US). An attacker can elevate privileges, which can result in full control of the HRMS application and its data, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is Oracle HRMS (US) in Oracle E-Business Suite, specifically internal operations components. Versions 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS 3.1 score of 7.2 indicates a high severity rating. The EPSS score of < 1% suggests a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based via HTTP, requiring high privileged access within the network. If exploited successfully, the attacker could take over the HRMS (US) application and its underlying data.
OpenCVE Enrichment