Impact
Oracle iRecruitment, a component of Oracle E‑Business Suite, has a vulnerability that allows a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to data and modify records. The flaw is easily exploitable and can lead to confidentiality loss for critical recruitment data and, with the scope change, potentially affect other Oracle products. The weakness is tied to improper access control, allowing exploitation with minimal effort and resulting in high impact to confidentiality; integrity is also impacted, while availability is unaffected.
Affected Systems
The affected product is Oracle Corporation's Oracle iRecruitment, part of the Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are vulnerable. These releases correspond to the 12.2 security patch set.
Risk and Exploitability
The CVSS base score is 8.5, indicating a high severity vulnerability. The exploitability score is very low (<1% EPSS), and the flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. Attackers would need only network connectivity to the HTTP interface and low‑privilege credentials; this makes the vulnerability trivial for attackers within the organization’s network. With the scope change, a successful compromise can provide unauthorized read or write access to all data exposed by Oracle iRecruitment and potentially other Oracle products.
OpenCVE Enrichment