Impact
A flaw exists in the Oracle Scheduler Rules UI component that can be exploited by an attacker who has a low‑privilege account and network connectivity over HTTP. The weakness allows unauthorized updates, inserts, deletions and restricted reads of Scheduler data, and can also trigger a partial denial of service. These capabilities affect confidentiality, integrity, and availability, and stem from improper enforcement of access control requirements.
Affected Systems
Oracle Scheduler, part of Oracle E‑Business Suite, is impacted for versions 12.2.3 through 12.2.15. The vulnerability is confined to the Rules UI feature of Scheduler, which is reachable via standard web requests.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while an EPSS score of less than 1% signals a low probability of exploitation today. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage standard HTTP traffic to the Scheduler service; no elevated credentials, privileged permissions, or remote code execution are required. Successful exploitation results in unauthorized data modification, limited read access, and a partial availability impact.
OpenCVE Enrichment