Impact
An easily exploitable weakness in Oracle Content Manager allows an attacker with a low‑privilege account and network access to perform unauthorized create, read, update, and delete operations against data stored in the system, as well as to trigger a partial denial of service. The impact spans confidentiality, integrity, and availability of the data managed by the Content Manager component.
Affected Systems
Oracle Content Manager, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. The vulnerability resides in the Cover Letter component of the product.
Risk and Exploitability
The CVSS base score of 6.3 signals a moderate severity, while the EPSS value of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an active HTTP session and a recognized low‑privilege account; the attacker can then bypass authorization controls to alter or read data and cause a limited service disruption.
OpenCVE Enrichment