Impact
A flaw in Oracle Enterprise Asset Management allows an attacker who can reach the web interface and has low‑privileged access to obtain full control over the application. The weakness is an improper access control that permits privileged operations for low‑privileged users, leading to compromise of confidentiality, integrity, and availability of asset management data and services.
Affected Systems
Oracle Corporation’s Enterprise Asset Management component of the Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 contain the vulnerability and any installation within this range is vulnerable.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 8.8, indicating high severity, and a very low EPSS probability of under 1%. The vulnerability is not listed in CISA KEV, but its remote HTTP access vector and low privilege requirement mean that a broad range of network users could potentially exploit it, resulting in full application takeover.
OpenCVE Enrichment