Impact
A vulnerability exists in Oracle HRMS (US) of Oracle E‑Business Suite, specifically in the US Payroll – General component. The flaw allows an attacker who already has high privileged network access via HTTP to take over the HRMS (US) instance. Successful exploitation gives the attacker control over the system, resulting in full confidentiality, integrity and availability compromise for the affected HRMS components. The CVSS 3.1 base score of 8.0 reflects the severe impact on all three security objectives.
Affected Systems
Affected vendors include Oracle Corporation, product Oracle HRMS (US). The impacted product range is Oracle E‑Business Suite HRMS versions 12.2.3 through 12.2.15. The vulnerability resides in the US Payroll – General module, and due to a scope change, related Oracle products could also be impacted. Only the US region deployment of HRMS is listed as affected, and no other vendors or products are cited.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity threat. Exploitability is classified as difficult, requiring an attacker to possess high privileged access and to reach the system over HTTP. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, the combination of high impact and the ability to compromise HRMS (US) warrants close monitoring and swift remediation. The vector requires network access in an internal or trusted environment, so securing HTTP interfaces and limiting privileged accounts are critical mitigation points.
OpenCVE Enrichment