Impact
A vulnerability in Oracle Advanced Pricing arises from a CWE-284 weakness – improper access control – where the application fails to enforce proper authorization checks. As a result, an unauthenticated attacker with network access via HTTP can modify, insert or delete data and read a subset of accessible data, leading to confidentiality and integrity impacts. The flaw yields a CVSS 3.1 base score of 6.5, indicating medium severity.
Affected Systems
Oracle Advanced Pricing components of Oracle E‑Business Suite, specifically the Price List module, are impacted for versions 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability is explo via a network‑based HTTP request without authentication, implying that any host on the public or internal network could potentially trigger it. The EPSS score of less than 1% indicates that exploitation probability is currently very low, and the vulnerability is not listed in the CISA KEV catalog. Despite the low likelihood, the potential for unauthorized data modification and disclosure warrants monitoring and remediation.
OpenCVE Enrichment