Impact
The flaw resides in Oracle Site Hub’s Site Hierarchy Flows component and is caused by an insufficient access‑control check (CWE‑284). An attacker with low system privileges who can reach the web interface via HTTP can create, read, update, or delete data that should be protected. Successful exploitation can alter or delete confidential content, expose sensitive records, and trigger a temporary denial of service that disrupts Hub availability.
Affected Systems
Affected products are Oracle Site Hub, part of Oracle E‑Business Suite, for releases 12.2.3 through 12.2.15. These versions contain the unpatched Site Hierarchy Flows code that permits the described operations. Higher‑level releases are not listed as vulnerable by Oracle.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. An EPSS score of < 1 % suggests a very low likelihood of active exploitation at present, and the issue is not in the CISA KEV catalog. Nevertheless, the vulnerability can be reached over the network via HTTP without special setup, so a compromised network segment could use this flaw to alter data or interrupt service. The risk to data integrity and business continuity remains significant.
OpenCVE Enrichment