Impact
Oracle Enterprise Asset Management suffers an authorization flaw that allows an attacker with low privileges and network access via HTTP to update, insert, or delete data and read restricted information, provided a human actor other than the attacker participates in the process. The flaw provides both confidentiality and integrity impact, enabling unauthorized manipulation of Asset Management data.
Affected Systems
The affected vendor is Oracle Corporation. The product is Oracle Enterprise Asset Management, part of the Oracle E‑Business Suite, specifically the Internal Operations component. Versions from 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The vulnerability carries a 5.4 CVSS‑3.1 score and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalog. The attack requires HTTP network connectivity and low privileged credentials, and the attack vector involves probable human interaction. The scope change indicates that successful exploitation could affect additional Oracle products beyond Enterprise Asset Management.
OpenCVE Enrichment