Impact
The Oracle Partner Management product is vulnerable in the Partner Dashboard component. A low‑privileged attacker with HTTPS network access can perform unauthorized update, insert or delete operations, read protected data, and trigger a partial denial of service. The flaw is due to missing access control checks, reflected in CWE‑284.
Affected Systems
Affected versions of Oracle Partner Management are 12.2.3 through 12.2.15. The product is part of Oracle E‑Business Suite and is maintained by Oracle Corporation.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerability via HTTPS from the network, requiring only low privileged credentials. Successful exploitation would grant unauthorized data manipulation, read access to sensitive information, and could cause a partial denial of service to the Partner Management system.
OpenCVE Enrichment