Impact
A flaw in the Bill Issues component of Oracle Bills of Material, an inappropriate access control weakness (CWE‑284), allows an attacker who can execute low‑privilege operations over the network via HTTP to take full control of the application. The vulnerability is classified with CVSS 3.1 score 8.8 and vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating complete compromise of confidentiality, integrity and availability.
Affected Systems
Oracle Bills of Material, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The product is provided by Oracle Corporation.
Risk and Exploitability
The EPSS score is reported as < 1 %, showing that actual exploitation is currently considered unlikely, and the vulnerability is not in the CISA KEV catalog. Nevertheless, since the attack requires only network access over HTTP, a low‑privilege attacker could walk the path to compromise if the service is reachable from outside the trusted network. The high CVSS score reflects its severe impact once exploited.
OpenCVE Enrichment