Impact
Oracle Public Sector Human Resources contains a flaw in its regression‑testing component that allows a high‑privileged attacker who can reach the application over HTTP to create, delete, or modify critical data. Based on the description, it is inferred that the vulnerability arises from an authorization failure, as it permits actions beyond the attacker’s authorized scope. This leads to unauthorized data modification and full access to all personnel records, exposing both confidentiality and integrity.
Affected Systems
Oracle Public Sector Human Resources version 12.2.3 through 12.2.15 is affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates significant confidentiality and integrity impact. Exploitation requires a high‑privileged user with network access over HTTP; the flaw is difficult to exploit and the EPSS score is <1%, indicating very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the scope change means a successful attack could affect other Oracle systems. The attacker could permanently alter data or authorize additional privileged actions within the application.
OpenCVE Enrichment