Impact
Oracle Price Protection in Oracle E‑Business Suite contains a flaw that permits a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data. The vulnerability enables unauthorized manipulation of data and can expose all information that the component can access, thereby compromising confidentiality and integrity.
Affected Systems
The affected product is Oracle Price Protection, part of Oracle E‑Business Suite’s Internal Operations component. Versions 12.2.3 through 12.2.15 are impacted; only installations of these releases should be verified for the presence of the flaw.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attacks are likely performed over HTTP with only low privileges required, and the main risk lies in confidentiality and integrity violations, with no availability impact.
OpenCVE Enrichment