Impact
The Oracle SDP Number Portability component exposes a web interface that can be exploited by low‑privileged users with network access via HTTP. Attackers can perform unauthorized update, insert or delete operations on data accessible through the component, and the flaw can also be used to cause a partial denial of service. The result is a compromise of the data integrity and availability of the service.
Affected Systems
Oracle SDP Number Portability of Oracle E-Business Suite, versions 12.2.3 to 12.2.15. The affected component is part of the installation package and includes a network‑exposed HTTP endpoint.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity, with impacts on integrity and availability. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network attack over HTTP, requiring only low privileges to achieve unauthorized changes or service disruption.
OpenCVE Enrichment