Impact
The Oracle US Federal Human Resources product, a component of Oracle E‑Business Suite, contains a flaw in its Internal Operations module that allows an attacker with only low privileges and network connectivity over HTTP to create, delete or modify critical data, as well as read a subset of that data. This vulnerability can lead to integrity loss and exposure of confidential information, as explicitly noted in Oracle’s advisory.
Affected Systems
Versions 12.2.3 through 12.2.15 of Oracle US Federal Human Resources are affected. The vulnerability is limited to Oracle Corporation’s product; no other vendors or applications are mentioned.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity due to low attack complexity and local privilege. The EPSS score of less than 1% suggests exploitation is currently rare, and the issue is not listed in CISA’s KEV catalog. Nevertheless, because the attack vector is network‑based over HTTP and requires only low privileges, the risk remains significant for systems exposed to potentially hostile networks, warranting prompt remediation.
OpenCVE Enrichment