Impact
Oracle Performance Management's Appraisals component contains a broken access control flaw that permits a low‑privileged attacker with network access over HTTP to perform unauthorized updates, inserts, deletions, and read operations against certain managed data. The vulnerability, identified as CWE‑284, does not require privileged credentials or local access. Successful exploitation can lead to alteration of appraisal records, tampering with performance metrics, or leakage of sensitive data, thereby impacting data integrity and confidentiality.
Affected Systems
Oracle Performance Management, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The Appraisals module is specifically impacted. Organizations using these versions should verify their installed software corresponds to the affected range.
Risk and Exploitability
The CVSS base score of 5.4 indicates a moderate impact with low confidentiality and integrity effects, and the attack vector is network through HTTP. The EPSS score below 1% suggests a very low current probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who already has network reach to the application and a low‑privileged account can exploit the flaw with minimal effort to modify or read appraisal data, making the scenario realistic for organizations that do not enforce stringent role‑based access controls on the Performance Management module.
OpenCVE Enrichment