Impact
Based on the description, the likely attack vector is low‑privilege network access via HTTP. Oracle HRMS (UK) Payroll contains an improper access control flaw that lets a user with low privileges and network connectivity via HTTP gain unauthorized access to HR data and perform creation, deletion or modification operations. This results in loss of confidentiality and integrity of critical HR information, as the attacker can alter or delete records at will.
Affected Systems
The flaw affects Oracle HRMS (UK) versions 12.2.3 through 12.2.15, which are part of Oracle E‑Business Suite. These versions expose administrative interfaces over HTTP, and while the vulnerability is localized to HRMS, the vector can change scope, enabling attacks against other Oracle components that interact with HRMS data.
Risk and Exploitability
Based on the description, the likely attack vector is low‑privilege network access over HTTP. With a CVSS base score of 9.6, the vulnerability is rated Critical. The EPSS score of less than 1 % indicates a very low but non‑zero exploitation probability, and it is not yet listed in CISA’s KEV catalog. Successful exploitation requires only low‑privilege network access over HTTP and no user interaction, meaning an attacker can remotely modify critical HR data from outside the trusted network.
OpenCVE Enrichment