Impact
The Oracle Quality product of Oracle E‑Business Suite contains a flaw that enables a low‑privileged attacker with network access via HTTP to take over the system. The vulnerability can compromise confidentiality, integrity, and availability, allowing the attacker to fully control Oracle Quality. The CVSS 3.1 vector indicates that the weakness is exploitable over the network with low effort and low privileged attacker.
Affected Systems
Affected versions range from 12.2.3 through 12.2.15 of Oracle Quality. The product resides within the Internal Operations component of Oracle E‑Business Suite and is deployed by organizations that manage Oracle Quality processes.
Risk and Exploitability
The CVSS base score of 8.8 marks this issue as high severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the near term. Nevertheless, the vulnerability is listed in Oracle’s security alert and is not part of the CISA KEV catalog. Because the flaw is remotely exploitable over HTTP without local privileges, any machine that hosts Oracle Quality and is reachable from outside the trusted network faces a serious risk of compromise.
OpenCVE Enrichment