Impact
A vulnerability exists in the Oracle HRMS (UK) component of Oracle E‑Business Suite that allows an attacker with low privileges and network access over HTTP to bypass access controls and disclose sensitive payroll data. The weakness is rooted in improper authentication and information disclosure, enabling an attacker to obtain confidential data or, depending on the scope change, potentially full access to all HRMS (UK) data.
Affected Systems
Oracle HRMS (UK) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. These versions expose the vulnerability over the network via HTTP, and they may impact other related products due to a scope change.
Risk and Exploitability
The CVSS v3.1 score of 7.7 indicates a high risk to confidentiality, with attackers needing only network access and low privilege to succeed. The EPSS score of less than 1% suggests that exploitation is presently unlikely, and the vulnerability is not listed in CISA KEV. However, because the attack vector is plain HTTP and the vulnerability relies on weak authentication, a determined adversary could obtain access and potentially expand the attack scope to other components.
OpenCVE Enrichment