Impact
The flaw in Oracle HRMS (US) Payroll Year End allows a low‑privileged attacker who can reach the system over HTTP to read critical HR data and, in some cases, to insert, update or delete records. This leads to confidentiality loss and integrity compromise of personnel information.
Affected Systems
Oracle HRMS (US) of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are marked as vulnerable by the CNA.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a high confidentiality impact, low integrity impact, and no availability impact. The EPSS score is below 1 %, suggesting a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can be achieved remotely over HTTP by an attacker with a low‑privileged account or the ability to authenticate to the system.
OpenCVE Enrichment