Impact
The flaw in Oracle HR Intelligence allows an attacker with low privileges and network access via HTTP to create, delete, or modify critical data and to cause the application to hang or crash repeatedly. The vulnerability is classified as improper access control (CWE-284) and can lead to significant integrity and availability damage.
Affected Systems
Oracle HR Intelligence, a component of Oracle E‑Business Suite Internal Operations. Versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 Base Score of 6.8 highlights medium overall risk with high impact on integrity and availability. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. Successful exploitation requires an attacker to be able to reach the Oracle HR Intelligence service over the network and to authenticate as a low‑privileged user, after which the attacker can perform unauthorized data operations or trigger a denial of service.
OpenCVE Enrichment