Impact
The Oracle Application Object Library in Oracle E‑Business Suite contains a flaw in the Core component that enables a low‑privileged attacker with network access to an HTTP interface to gain unauthorized privileges. The flaw is a CWE‑284: Improper Access Control vulnerability. The vulnerability permits an attacker to update, insert, delete or read data accessible through the library, potentially exposing confidential information or corrupting database integrity. The CVSS 3.1 score of 5.4 reflects moderate severity with modest confidentiality and integrity impacts but no availability effect.
Affected Systems
Oracle Corporation’s Application Object Library, versions 12.2.3 through 12.2.15, are affected. These releases expose HTTP endpoints that, if reachable, allow a low‑privilege attacker to manipulate or read data.
Risk and Exploitability
EPSS shows a probability of exploitation below 1 % and the issue is not listed in the CISA KEV catalog, which reduces the likelihood of widespread exploitation. The attack vector is inferred to be network‑based: an attacker needs only HTTP connectivity to craft special requests that bypass access controls. Should the vulnerability be exploited, the attacker would compromise the confidentiality and integrity of the library’s data but would not affect availability.
OpenCVE Enrichment