Impact
Oracle EDI Gateway, part of Oracle E-Business Suite, contains a CWE-284 vulnerability that allows a low-privileged attacker with network access over HTTP to compromise the system. Successful exploitation enables the attacker to create, delete, or modify critical data, thereby violating confidentiality and integrity of all data accessible through the gateway. The CVSS 3.1 base score is 8.1, reflecting a high severity level.
Affected Systems
The affected product is Oracle EDI Gateway, an Oracle E-Business Suite component, with versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability can be exploited remotely with only network access via HTTP and low privileges, making it relatively easy to attack. The EPSS score of less than 1% indicates a low probability of widespread exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. If exploited, the attacker gains unauthorized creation, deletion, or modification access to all data accessible through the gateway.
OpenCVE Enrichment