Impact
The vulnerability resides in Oracle Contracts Integration, a component of Oracle E‑Business Suite, and allows a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to a full takeover of Oracle Contracts Integration, affecting confidentiality, integrity, and availability. The flaw also carries a scope change, meaning attacks may influence additional related products, amplifying the potential damage.
Affected Systems
The affected product is Oracle Contracts Integration. Supported releases from version 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score is 8.5, indicating a high‑severity vulnerability. The EPSS score is less than 1 %, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is network‑based through the HTTP interface, requiring only low‑privilege credentials and no user interaction. Although exploitation is difficult, the potential impact is severe, warranting immediate assessment and mitigation once a patch is issued.
OpenCVE Enrichment