Impact
The vulnerability in Oracle’s Process Manufacturing Product Development component allows an attacker with only low privileges and network access via HTTP to fully compromise the system. The flaw can lead to a takeover of the application, exposing all confidential data, enabling modification of business processes, and disrupting service availability.
Affected Systems
Oracle Process Manufacturing Product Development, Oracle E-Business Suite component Internal Operations, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score of less than 1% suggests the probability of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack vector is a network-facing HTTP service and the privilege requirement is minimal, the risk remains high. Compromise can also extend to other Oracle products due to the change of scope.
OpenCVE Enrichment