Impact
Oracle HRMS (US) in the Oracle E‑Business Suite contains a vulnerability that allows a high‑privileged attacker with HTTP network access to read all data that the user can normally access. The flaw, documented as affecting versions 12.2.3 through 12.2.15, can lead to an unauthorized disclosure of confidential business information. The weakness maps to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).
Affected Systems
Version 12.2.3 to 12.2.15 of Oracle HRMS (US) within the Oracle E‑Business Suite, particularly the Internal Operations component, is impacted. Because the CVE notes a scope change, other related products in the suite may also be affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.8 designates this vulnerability as medium severity with a primary confidentiality impact. The EPSS score of less than 1 % signals a low likelihood of exploitation in the wild, and it is not currently listed in CISA’s KEV catalog. The likely attack vector is over HTTP, and it requires that the adversary already possess high‑privileged credentials or obtain them through an unrelated compromise. If exploited, the attacker can access all HRMS (US) data visible to that account, potentially exposing sensitive employee and financial information.
OpenCVE Enrichment