Impact
The vulnerability in Oracle Common Application Components allows a low‑privileged attacker with network access over HTTP to perform unauthorized creation, deletion or modification of data stored in the component. The flaw effectively bypasses access control checks, compromising confidentiality, integrity, and limiting availability of critical application data. This flaw does not require elevated privileges but requires the attacker to possess a low‑privilege account or credential to access the component.
Affected Systems
Oracle Common Application Components within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.4 indicates high severity, with impacts on confidentiality, integrity, and availability. The EPSS is less than 1 %, implying a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would typically exploit HTTP traffic, leveraging the low‑privilege breach to change data or trigger a partial denial of service; the scope change enables broader impact beyond the immediate component.
OpenCVE Enrichment