Impact
A flaw in Oracle Project Costing’s Enterprise Command Center permits a high‑privileged attacker with HTTP network access to compromise the application and potentially assume full control. The vulnerability provides simultaneous loss of confidentiality, integrity, and availability, as reflected by a CVSS v3.1 base score of 7.2 and a vector emphasizing an unauthenticated attack from a network location.
Affected Systems
Affected versions span 12.2.3 through 12.2.15 of Oracle Project Costing. The exposed HTTP interface of the Enterprise Command Center is the entry point for exploitation, so any deployment of these releases is vulnerable unless mitigated.
Risk and Exploitability
The Mod‑hard to exploit risk is moderate, driven by a low EPSS score (< 1 %) yet a high CVSS severity. The flaw is not listed in the CISA KEV catalog. An attacker who already holds high‑privileged credentials can exploit the issue remotely without user interaction, relying only on standard HTTP connectivity.
OpenCVE Enrichment