Impact
This vulnerability in the Common Utilities component of Oracle Complex Maintenance, Repair and Overhaul allows a low‑privileged attacker with network access via HTTP to gain unauthorized update, insert, delete and read access to Oracle data. The weakness is a flaw in access control (CWE‑284), resulting in moderate confidentiality and integrity impacts reflected by the CVSS base score of 5.4.
Affected Systems
Affected systems are Oracle E‑Business Suite’s Oracle Complex Maintenance, Repair and Overhaul product, version range 12.2.3 to 12.2.15. The Common Utilities component is the entry point for the vulnerability and is accessible over HTTP.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, and the EPSS score of <1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Exploitation requires only network connectivity to the HTTP interface and low privileges, so the likely attack vector—based on the description—is limited to internal or compromised network segments.
OpenCVE Enrichment