Impact
A flaw in the Internal Operations component of Oracle HRMS (US) permits a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to sensitive information. The vulnerability does not affect integrity or availability but allows the attacker to read critical HR data or, in the worst case, all data exposed by the application. The weakness is an information disclosure (CWE‑200) combined with insufficient access control (CWE‑284).
Affected Systems
Oracle Corporation’s HRMS (US) component of Oracle E‑Business Suite, specifically versions 12.2.6 through 12.2.15, are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based via HTTP, requiring only low privileges on the network. The risk to organizations depends on the exposure of the HRMS application to the network and the sensitivity of the data it handles. Organizations with publicly accessible HRMS services face a higher risk than those that restrict access to internal networks.
OpenCVE Enrichment