Impact
Oracle Enterprise Asset Management (part of Oracle E‑Business Suite) has a flaw in its Internal Operations component that permits an attacker who already has high‑level privileges and network connectivity over HTTP to compromise the application. The issue is an access‑control problem, identified as CWE‑284, allowing the attacker to bypass intended authorization controls and create, delete, or modify critical data, as well as read all data stored in the application. The CVSS 3.1 vector indicates confidentiality and integrity impact metrics without an availability impact, reflecting the destructive potential of the vulnerability on data integrity and confidentiality.
Affected Systems
The affected vendor is Oracle Corporation and the product is Oracle Enterprise Asset Management. Versions 12.2.3 through 12.2.15 are affected. The flaw exists in the internal operations component of this product.
Risk and Exploitability
The CVSS 3.1 Base Score of 5.9 denotes moderate severity, with confidentiality and integrity impact metrics. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this analysis. The vulnerability is not recorded in the CISA KEV catalog. The likely attack vector is over the internal network via HTTP and requires that the attacker already possess high privileges within the environment, so exploitation is limited to internal or privileged threat actors.
OpenCVE Enrichment