Impact
The vulnerability resides in the Cost Maintenance module of Oracle Cost Management, a component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected. The flaw allows a low‑privileged attacker who can reach the application over HTTP to compromise Oracle Cost Management, resulting in full takeover of the service. The weakness is an improper access control (CWE‑284) that undermines confidentiality, integrity, and availability of cost data.
Affected Systems
Oracle Cost Management within Oracle E‑Business Suite, specifically versions 12.2.3 to 12.2.15. The issue is confined to the Cost Maintenance component, and only the supported releases in that range are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity impact. An EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker with network access to the HTTP interface to compromise the application.
OpenCVE Enrichment