Impact
A flaw in Oracle HCM Common Architecture permits an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data, including the ability to read, insert, update, or delete certain datasets, thereby impacting confidentiality and integrity. This vulnerability represents an authorization weakness (CWE-284).
Affected Systems
Oracle Corporation's Oracle HCM Common Architecture versions 12.2.3 through 12.2.15 are affected. The vulnerability resides in the Knowledge Integration component.
Risk and Exploitability
The CVSS base score of 8.2 reflects substantial impact. The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based HTTP traffic where no authentication is required, making exploitation straightforward for an attacker within network reach.
OpenCVE Enrichment