Impact
A flaw in Oracle HRMS (US) permits a low‑privileged attacker with network access via HTTP to bypass or circumvent access controls and obtain sensitive data. The vulnerability is rated CVSS 3.1 with a base score of 6.5 and primarily affects confidentiality.
Affected Systems
Systems running Oracle HRMS (US) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are impacted. Affected installations expose the internal operations component to HTTP traffic.
Risk and Exploitability
The attack vector is an HTTP endpoint, requiring low privileged credentials. While the EPSS score is less than 1% indicating low current exploitation probability, the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 6.5 highlights a medium severity risk with potential unauthorized data exposure. No additional prerequisites beyond network access to the HRMS HTTP interface are described.
OpenCVE Enrichment