Impact
The Oracle HRMS (India) product contains a flaw in the Internal Operations component that permits a low‑privileged attacker with network access over HTTP to bypass normal authentication and gain unauthorized read, update, insert, or delete rights on data that should be protected. The flaw grants confidentiality impacts for all data accessible through the component and can enable data tampering, potentially extending the compromise to other integrated products due to a scope change.
Affected Systems
This issue affects Oracle HRMS (India) versions 12.2.3 through 12.2.15. Only the HRMS India component is directly vulnerable but other integrated products may experience impact as a result of the scope change.
Risk and Exploitability
The CVSS v3.1 base score of 8.5 indicates high severity for confidentiality and integrity, while the EPSS score of less than 1 % suggests exploitation is presently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a low‑privileged HTTP request as described in the advisory. If exploited, an attacker can obtain full read or modify access to all data exposed by Oracle HRMS (India). The flaw resides in the internal operations path, making privilege elevation and accidental data exposure the main risks.
OpenCVE Enrichment