Impact
A flaw in Oracle HRMS (UK) component of Oracle E‑Business Suite – specifically the UK Payroll module – permits a low‑privileged attacker with network access via HTTP to read and modify protected HR data. The vulnerability, classified as an authorization flaw (CWE‑284), enables disclosure of confidential information and integrity violations such as unauthorized updates, inserts, or deletions of critical HR records.
Affected Systems
Oracle Corporation’s Oracle HRMS (UK) component of the E‑Business Suite is affected for all supported releases from version 12.2.3 through 12.2.15. Any system running one of these releases must be inspected to confirm vulnerability status.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a high severity rating, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low but non‑zero exploitation probability. The attack vector is network delivery over HTTP; a low‑privileged user can exploit the issue remotely without authentication, making the risk significant for exposed services.
OpenCVE Enrichment