Impact
A flaw in the Project Definition component of Oracle Project Foundation permits a low‑privileged attacker with network access via HTTP to modify, insert, or delete data, read restricted data, and induce a partial denial of service. This vulnerability has been rated as having moderate impact on confidentiality, integrity, and availability, as reflected in the CVSS 3.1 base score of 6.3.
Affected Systems
Oracle Project Foundation, part of Oracle E‑Business Suite, is affected. All supported builds from version 12.2.3 through 12.2.15 contain the vulnerability.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate risk while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based over HTTP and requires only low privileged access to the target system.
OpenCVE Enrichment