Impact
Oracle Content Manager in Oracle E‑Business Suite is vulnerable to a low‑privilege attacker over HTTP via an improper access control flaw (CWE‑284). The flaw permits unauthorized creation, deletion, or modification of content and can grant full access to all data exposed by the application, compromising confidentiality and integrity. The vulnerability is classified as a high‑severity issue with a CVSS 3.1 score of 8.1, reflecting strong potential impact on data security.
Affected Systems
Oracle Content Manager, versions 12.2.3 through 12.2.15, within the Oracle E‑Business Suite, are affected. The vulnerability impacts all deployments of these versions that are reachable over HTTP.
Risk and Exploitability
The CVSS score of 8.1 indicates a high level of risk. The EPSS value is below 1%, suggesting that automated exploitation is currently rare, though manual exploitation is still feasible. The issue is not currently listed in the CISA KEV catalog, which may reflect a lower observed exploitation rate. Attackers require only low network privileges and need HTTP access to the vulnerable instance, making the threat vector straightforward for attackers who can reach the application over the network.
OpenCVE Enrichment