Impact
A flaw in Oracle iSupport of Oracle E‑Business Suite lets an unauthenticated attacker with network access via HTTP potentially compromise the application. The functionality requires the attacker to rely on an outside human user to trigger the exploitation, but once active it can grant unauthorized insert, update or delete rights on data accessible through iSupport as well as read access to a subset of that data. The weakness involves misconfigured access controls (CWE‑284) coupled with cross‑site request forgery (CWE‑352) and unreliable redirect handling (CWE‑601).
Affected Systems
The vulnerability affects Oracle iSupport for Oracle E‑Business Suite, impacting all installed versions from 12.2.3 up through 12.2.15. These versions support the Internal Operations component and are reachable over standard HTTP ports.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 indicates moderate confidentiality and integrity impact. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. However, the need for a human interaction to complete the attack does not eliminate risk, and the potential for data tampering and disclosure warrants timely remediation.
OpenCVE Enrichment