Impact
The vulnerability resides in the Web Service Provider component of Oracle E‑Business Suite Integrated SOA Gateway and is caused by improper authorization checks, a CWE‑284 authority control weakness. An attacker with low‑privilege credentials and network access via HTTP can execute update, insert, or delete operations on data that should be protected, read restricted data, and trigger a partial denial of service. This results in compromise of the confidentiality, integrity, and availability of the gateway’s data and services.
Affected Systems
Oracle E‑Business Suite Integrated SOA Gateway versions from 12.2.3 through 12.2.15 are vulnerable. The issue applies to all installations of these versions regardless of deployment configuration.
Risk and Exploitability
Based on the description, the likely attack vector is a network‑based HTTP request sent by a low‑privilege user. The CVSS V3.1 score of 6.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Successful exploitation would allow data tampering, unauthorized data disclosure, and a partial denial of service of the gateway.
OpenCVE Enrichment