Impact
An Oracle HRMS (India) vulnerability permits a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data, as well as to read all accessible data. This issue stems from misconfigured access control (CWE‑284). The CVSS v3.1 base score of 8.1 indicates high confidentiality and integrity impact with no availability impact.
Affected Systems
The flaw exists in Oracle HRMS (India) component of Oracle E‑Business Suite for supported releases 12.2.3 through 12.2.15. These versions are vulnerable to the described misuse of administration functions.
Risk and Exploitability
The CVSS score of 8.1 reflects a serious risk, yet the EPSS probability of exploitation is below 1%, suggesting low current threat activity. The vulnerability is not catalogued in the CISA KEV list. The attack requires only network connectivity to the HTTP interface and a low‑privileged account, implying that networks with exposure to Oracle HRMS (India) may be susceptible.
OpenCVE Enrichment