Impact
A low‑privileged attacker with network access to the HTTP interface of Oracle HRMS (Norway) can exploit an access‑control flaw to read all data stored in the system. The weakness is linked to insufficient authentication checks and inadequate separation of privileges, as reflected in CWE‑200 and CWE‑284. The flaw also carries a scope change, indicating that exploitation may affect other components of the Oracle E‑Business Suite as well.
Affected Systems
Oracle HRMS (Norway), part of Oracle E‑Business Suite Internal Operations, is affected for versions 12.2.3 through 12.2.15. The product is accessed over HTTP and distributed by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 classifies the vulnerability as high severity. An EPSS score of less than 1 % signals that exploitation is currently considered unlikely. The flaw is not listed in the CISA KEV catalog. An attacker requires only network connectivity to the HTTP and a low‑privilege account to read sensitive data, making the attack path relatively straightforward.
OpenCVE Enrichment