Impact
Oracle Process Manufacturing Regulatory Management suffers from a vulnerability that allows an attacker with low privileges and network access via HTTP to gain unauthorized access to critical or all accessible data. The flaw permits compromise of confidential data without affecting integrity or availability. Further exploitation might enable lateral movement to other systems, though this is inferred from the potential scope change highlighted in the CVE description.
Affected Systems
Affected versions include Oracle Process Manufacturing Regulatory Management 12.2.3 through 12.2.15. The product is part of Oracle E-Business Suite’s Internal Operations component.
Risk and Exploitability
The CVSS 3.1 score of 7.7 indicates a high severity with a significant confidentiality impact. The low exploitation complexity and network attack vector mean that any host with HTTP access to the service could exploit the flaw. EPSS is below 1%, suggesting current exploit prevalence is low, and the vulnerability is not listed in the CISA KEV catalog. The potential scope change noted in the description suggests a risk to other Oracle products, making patching a priority.
OpenCVE Enrichment