Impact
The vulnerability is an improper authorization flaw (CWE-284) that can be exploited by an attacker who already possesses high-level privileges and can reach the application over HTTP. When successfully leveraged, the flaw allows the attacker to bypass intended access controls, resulting in full compromise of the confidentiality, integrity, and availability of Oracle Public Sector Financials (International). The impact may also extend to other Oracle E-Business Suite components if the exploit propagates beyond the original product boundary.
Affected Systems
Affected installations are Oracle Public Sector Financials (International) versions 12.2.3 through 12.2.15. The product is part of Oracle E-Business Suite, and because the vulnerability carries a scope change, additional Oracle products could be indirectly impacted if the exploit chain crosses product boundaries.
Risk and Exploitability
The CVSS-3.1 base score of 8.0 indicates high severity with fatal consequences for confidentiality, integrity, and availability. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, meaning no known public exploits are reported. Attackers would need high-level privileges and network access to the HTTP endpoint, making the threat more targeted than a mass‑assail scenario. Nonetheless, the scope change possibility means that once an attacker gains initial access, the breach could affect more than a single product.
OpenCVE Enrichment