Impact
This vulnerability allows an unauthenticated attacker who has physical access to the communication segment connected to the Oracle iRecruitment server to compromise the application. Successful exploitation enables the attacker to create, delete, modify, or otherwise access critical data managed by Oracle iRecruitment. The impact is a direct loss of confidentiality and integrity, as described by the CVSS vector that indicates high disclosure and integrity impacts with no availability effect.
Affected Systems
The affected products are Oracle Corporation’s Oracle iRecruitment component of Oracle E‑Business Suite, specifically the Internal Operations module. Versions 12.2.3 through 12.2.15 are documented as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 6.8 reflects moderate severity, while the EPSS score of < 1% indicates that, historically, the likelihood of exploitation is low and the vulnerability is not listed in the CISA KEV catalog. The described attack vector is adjacent network (AV:A), requiring the attacker to reach the server’s communication segment, indicating a local or near‑local threat. If the attacker can access this segment, the vulnerability can be leveraged to perform unauthorized data modification or access.
OpenCVE Enrichment