Impact
The vulnerability allows an attacker who already has high privileged credentials and network access via HTTP to fully compromise the Oracle HRMS Netherlands Payroll component. Successful exploitation results in complete takeover, exposing the system to all confidentiality, integrity, and availability impacts. The weakness arises from improper access control (CWE‑284) that permit a privileged attacker to exploit the system over the network without any user interaction.
Affected Systems
Oracle HRMS Netherlands component of Oracle E-Business Suite, versions 12.2.3 through 12.2.15, is affected. The vulnerability is present in the Netherlands Payroll module and applies to any environment that has these versions of the HRMS running.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates a high severity weakness that can be exploited with low effort by a high privileged attacker. The EPSS score of < 1% indicates a very low probability of exploitation, although the lack of a KEV listing does not mitigate the risk. The attack vector is inferred to be via the network through HTTP as the vendor notes network access can be used. The attacker must have high privileges; if so, the impact is total takeover of Oracle HRMS Netherlands.
OpenCVE Enrichment