Impact
This vulnerability in Oracle iRecruitment allows an attacker with limited privileges and network access over HTTP to create, delete, or modify critical data, or gain full access to all accessible data. A successful exploitation results in loss of confidentiality and integrity, potentially exposing sensitive recruitment information. The weakness stems from improper access control that fails to enforce adequate permission checks.
Affected Systems
Affected version range is Oracle iRecruitment 12.2.3 through 12.2.15. The issue appears in the Internal Operations component of Oracle E‑Business Suite and may still be in use by public and internal departments.
Risk and Exploitability
The CVSS v3.1 score of 8.1 classifies this as high severity; the attack vector is remote over the network using HTTP, with low attack complexity and requiring only low privileges. The EPSS score of <1% (approximately 0.4%) indicates a low probability of exploitation at this time, although the vulnerability is still described as easily exploitable. The risk to exposed iRecruitment instances remains significant, necessitating patching and proper privilege separation.
OpenCVE Enrichment