Impact
Oracle Applications Framework contains a flaw in the Upload Attachments component that enables a low‑privileged attacker with network access via HTTP to perform unauthorized update, insert, delete, or read operations on data exposed by the framework. The vulnerability—rated CVSS 3.1 with a base score of 4.6—reflects modest confidentiality and integrity impacts and requires human interaction from a user distinct from the attacker. An attacker can exploit the flaw only after a user has interacted with the application, making the attack window narrower but still viable for targeted campaigns. This flaw is a manifestation of CWE‑284, which indicates an unauthorized access weakness.
Affected Systems
The flaw affects Oracle E‑Business Suite Versions 12.2.8 through 12.2.15. All instances of Oracle Applications Framework within these releases are potentially vulnerable and should be identified in the environment.
Risk and Exploitability
With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of widespread exploitation is low, yet the potential for data integrity loss exists. The attack vector is likely network‑based, leveraging HTTP requests to the Upload Attachments endpoint, and requires the victim to initiate or complete a user interaction step. The moderate CVSS score reflects that the flaw does not allow full compromise but can lead to unauthorized data manipulation while keeping the attacker’s presence relatively covert. The CVSS base score is 4.6.
OpenCVE Enrichment