Impact
The vulnerability resides in the Internal Operations component of Oracle Process Manufacturing Inventory. An attacker with a low‑privilege account and network access can exploit the flaw to create, delete, or modify inventory records, or to view all data managed by the application. This compromises the confidentiality and integrity of the data, as the application does not enforce proper access control on the affected interface.
Affected Systems
All supported releases of Oracle Process Manufacturing Inventory within Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any deployment of these versions that is reachable over HTTP is potentially vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 reflects a high‑severity exposure that is network accessible with low‑privilege credentials. The EPSS score of less than 1% indicates an exceedingly low probability of automated exploitation at the time of analysis. Although not listed in the CISA KEV catalog, the vulnerability enables unauthorized manipulation of critical inventory data and therefore remains a serious risk for organizations reliant on accurate audit trails.
OpenCVE Enrichment