Impact
A flaw in Oracle Project Costing’s Enterprise Command Center allows a high‑privileged attacker with network access via HTTP to compromise the application, resulting in loss of confidentiality, integrity, and availability. The vulnerability can lead to full takeover of the application, effectively granting the attacker control over all project costing data and processes.
Affected Systems
Oracle Project Costing, part of Oracle E‑Business Suite, is affected in all supported versions from 12.2.3 through 12.2.15. Any deployment of these releases that exposes the Enterprise Command Center over HTTP remains vulnerable.
Risk and Exploitability
The CVSS v3.1 base score is 7.2, indicating substantial impact, while the EPSS score is below 1% and the issue is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. The flaw requires high‑privileged credentials and can be executed remotely without user interaction by sending malicious HTTP requests to the exposed interface. Therefore, internal or remote attackers with sufficient privileges pose the primary threat.
OpenCVE Enrichment