Impact
An attacker with only low privileges and network access to the Oracle iRecruitment service via HTTP can exploit a flaw that enables reading of critical data without proper authorization. The vulnerability resides in the Internal Operations component and is classified as an improper authorization weakness, resulting in a high confidentiality impact as all data exposed by the application can be accessed. The CVSS vector demonstrates a network-based attack with low complexity, low privileges, no user interaction, and a scope change that can affect other modules of the E‑Business Suite.
Affected Systems
Oracle iRecruitment versions 12.2.3 through 12.2.15 are affected. The product is part of Oracle E‑Business Suite, and the flaw exists in the Internal Operations component.
Risk and Exploitability
The CVSS base score of 7.7 marks this flaw as high severity. However, the EPSS score of less than 1 % and its absence from the CISA KEV catalog indicate a low likelihood of active exploitation at present. Nevertheless, because the attack vector is a simple HTTP request and only requires low privileges, the vulnerability is easily exploitable by anyone with network reach to the application. The scope change means successful exploitation could also impact other internal modules of the E‑Business Suite.
OpenCVE Enrichment