Impact
The vulnerability resides in Oracle Cost Management (Enterprise Command Center) version 16. A high‑privileged attacker who can reach the application over HTTP can exploit the flaw to create, delete, or modify critical data, compromising the confidentiality and integrity of all data accessible through the product and potentially disrupting business operations.
Affected Systems
Oracle Cost Management, part of Oracle E‑Business Suite, version 16 is impacted. The CPE string indicates the same. No other versions are mentioned.
Risk and Exploitability
The CVSS 3.1 base score is 6.5, reflecting high impact to confidentiality and integrity. The EPSS score is below 1%, suggesting limited publicly available exploit code. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires network access over HTTP and high privileged credentials; no remote code execution is described. The overall risk is moderate, but successful exploitation can lead to significant data loss or manipulation.
OpenCVE Enrichment