Impact
The vulnerability in the Internal Operations component of Oracle U.S. Federal Financials allows a low‑privileged attacker with network access via HTTP to create, delete or modify critical data. This results in unauthorized data manipulation and can expose all data accessible through the system, bypassing normal access controls and compromising confidentiality and integrity.
Affected Systems
Oracle U.S. Federal Financials, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
CVSS 3.1 Base Score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a low probability of exploitation so far, and the vulnerability is not listed in CISA KEV. Exploitation requires only network access over HTTP and low‑privilege credentials, leveraging an improper authorization weakness. Successful exploitation can grant the attacker full access to the application and allow unauthorized creation, deletion, and modification of all critical data.
OpenCVE Enrichment