Impact
A flaw in Oracle Enterprise Asset Management’s Work Definition Issues component permits a low‑privileged user with network access via HTTPS to perform unauthorized updates, inserts, deletes, or reads of certain data. The vulnerability can affect confidentiality and integrity by allowing data tampering and partial data disclosure, as quantified by a CVSS 3.1 base score of 5.4.
Affected Systems
Oracle Enterprise Asset Management (Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are impacted. Users of these releases should verify whether they are running a vulnerable build and check Oracle’s official CPU announcement for applicable patches.
Risk and Exploitability
The CVSS score indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The CVE is not listed in CISA’s KEV catalog. The likely attack path involves a remote attacker forging HTTPS requests to the vulnerable endpoint; no elevated privileges or prior authentication are required beyond those normally granted to a local user. Because the issue can lead to both modification and read access, it poses a tangible risk to data integrity and confidentiality for affected organizations.
OpenCVE Enrichment