Impact
Vulnerability in the Attachments component of Oracle Document Management and Collaboration allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data. Successful exploitation can lead to unauthorized modification of attachments or complete access to all data stored in the system. The weakness, a Broken Access Control flaw (CWE-284), results in loss of confidentiality and integrity but does not affect availability. CVSS 3.1 score of 8.1 reflects high severity with low attack complexity and little privilege requirement.
Affected Systems
Oracle Document Management and Collaboration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The fix is available in the July 2026 CPU update.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high risk posture. EPSS of less than 1 % suggests that the likelihood of live exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to be in the network and possess a low‑privileged user account to reach the HTTP endpoints that handle attachments, which is the most likely attack vector inferred from the description.
OpenCVE Enrichment