Impact
The Oracle General Ledger product of Oracle E‑Business Suite contains a flaw that permits an attacker with low privileges to invoke SOAP calls over the network. This flaw results in the compromise of Oracle General Ledger and allows full control over the application, causing loss of confidentiality, integrity, and availability. The weakness stems from improper access control (CWE‑269), weak authentication (CWE‑287), and missing authorization (CWE‑306).
Affected Systems
Affected products include Oracle General Ledger within Oracle E‑Business Suite's Internal Operations component. Versions from 12.2.3 through 12.2.15 are impacted. No other version information is provided.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The flaw requires network connectivity to the SOAP service and minimal user privileges; therefore, any system exposing the SOAP endpoint to the network can be at risk if the patch is not applied.
OpenCVE Enrichment