Impact
Improper access control in Oracle Interaction Blending enables a low‑privileged local attacker—one who has logged into the underlying system—to create, delete, or modify critical data. The flaw permits the attacker to gain complete read access to all data the component handles, breaching confidentiality and integrity. The weakness is identified as CWE‑284, a permission or access control issue.
Affected Systems
Oracle Interaction Blending, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15 in the Internal Operations module. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a medium‑high risk. Exploitation requires local access with low privileges and no user interaction; the attack vector is local. The EPSS score is below 1%, implying a very low probability of current exploitation, and the vulnerability is not recorded in the CISA KEV catalogue. Attackers must first obtain on‑premises access to the host running Interaction Blending, then exploit the access‑control flaw to perform data‑manipulation operations.
OpenCVE Enrichment