Impact
The vulnerability originates in Oracle HRMS (India) internal operations, enabling a low‑privileged attacker with network access over HTTPS to read or alter sensitive employee data. The flaw creates a confidentiality breach for critical information and allows integrity violations by permitting unauthorized update or deletion of HR data.
Affected Systems
Oracle Corporation’s Oracle HRMS (India) component of Oracle E‑Business Suite, affecting versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 classifies the weakness as high, with an attack surface limited to network traffic via HTTPS, low attack complexity, and low privilege requirements. Although the EPSS score is below 1% and the issue is not yet in CISA’s KEV catalog, the potential for significant data leakage and corruption makes it a critical concern for any organization that relies on Oracle HRMS (India).
OpenCVE Enrichment