Impact
Oracle Cost Management, specifically the Cost Planning component, contains a flaw that allows a low‑privileged attacker with network access via HTTP to compromise the application and gain full control. Successful exploitation results in the attacker taking over the entire Cost Management service, thereby undermining confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects Oracle E‑Business Suite Oracle Cost Management versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high‑severity flaw. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the issue is not listed within the CISA KEV catalog. The likely attack vector is a network‑based HTTP request, requiring only a low‑privileged account and no user interaction. The condition is that the attacker can reach the Cost Planning service over HTTP and use the flawed privilege controls to take over the system.
OpenCVE Enrichment