Impact
This vulnerability allows an attacker with a low‑privilege logon on the infrastructure where Oracle HRMS (US) executes to compromise the Payroll Tax Issues component of Oracle HRMS (US). Successful exploitation can lead to full takeover of the HRMS system, providing the attacker with complete access to confidential payroll data and the ability to manipulate or delete records. The CVSS 3.1 vector indicates local access, low authentication, and no user interaction, resulting in high confidentiality, integrity, and availability impact. The weakness is consistent with a local privilege escalation flaw, encompassed by CWE-284.
Affected Systems
Oracle Corporation’s Oracle HRMS (US) Payroll Tax Issues component of Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are specifically listed as vulnerable. Users of these releases should review patch status for their environment.
Risk and Exploitability
The CVSS base score of 7.8 marks this as a high‑severity issue. With an EPSS score of < 1 % the likelihood of exploitation is low, yet the vulnerability remains potentially exploitable if the infrastructure is accessible to an attacker and a low‑privileged account exists. The likely attack vector is local; an adversary must have a valid user session on the host or be able to log‑in through a compromised account to leverage the flaw.
OpenCVE Enrichment