Impact
The vulnerability resides in the Oracle iSetup product, specifically the General Ledger Update Transform and Reports components. It allows a low‑privileged attacker with network access through HTTP to compromise the system, leading to a full takeover of Oracle iSetup. This flaw arises from improper access control (CWE‑284) and results in confidentiality, integrity, and availability impacts, as reflected in the CVSS 3.1 vector
Affected Systems
Affected are Oracle E‑Business Suite installations using Oracle iSetup versions 12.2.3 through 12.2.15. Oracle customers deploying any of these releases with the General Ledger Update Transform or Reports components are at risk.
Risk and Exploitability
The CVSS base score of 8.8 signals a high severity vulnerability, though the EPSS score of <1% suggests a very low current exploitation probability. The attack can be conducted over the public network via HTTP with only low privileges, and the lack of listing in the KEV database indicates no publicly known exploits, but the potential impact warrants immediate attention.
OpenCVE Enrichment