Impact
The vulnerability exploits improper privilege management in Oracle HRMS (US). An attacker with local logon rights on the host running the HRMS can execute actions that grant them full control over the HRMS service. Successful exploitation results in confidentiality, integrity, and availability compromise, effectively allowing the attacker to take over the HRMS application. The weakness is categorized as CWE‑269.
Affected Systems
Oracle Corporation's Oracle HRMS (US) product, part of Oracle E‑Business Suite, is affected. Supported versions 12.2.3 through 12.2.15 are vulnerable. The issue resides in the Internal Operations component of HRMS.
Risk and Exploitability
The CVSS base score is 7.8, indicating high severity. The exploit confidence is low, with an EPSS score of less than 1%, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation. However, the attack vector requires only local access with low privileges; any user with a login on the host can potentially exploit the flaw. If the method is employed, the attacker can achieve full compromise of the HRMS application.
OpenCVE Enrichment