Impact
The Oracle Customer Interaction History product in Oracle E‑Business Suite contains a flaw in the Outcome‑Result component that permits a low‑privileged attacker with HTTP network access to perform unauthorized update, insert, delete, or read operations on accessible data. This flaw can compromise the confidentiality and integrity of customer interaction records, allowing an attacker to alter records or expose sensitive information. The vulnerability is identified as a low‑privileged access control bypass and results in a CVSS 3.1 base score of 5.4, with confidentiality and integrity impacts rated low.
Affected Systems
The affected versions are Oracle Customer Interaction History 12.2.3 through 12.2.15 in the Oracle E‑Business Suite. Any installation of these releases that has the Outcome‑Result component exposed over HTTP is potentially vulnerable. No other product or version is listed as affected.
Risk and Exploitability
The risk assessment shows a moderate severity CVSS score of 5.4 and an EPSS score of less than 1%, indicating that attempted exploitation is unlikely at this time. The vulnerability is currently not listed in CISA’s KEV catalog. The attack vector is a network interaction over HTTP and the requirement is a low‑privileged account within the Oracle E‑Business Suite. Because the flaw allows data modification and disclosure, it is advisable to apply mitigations promptly.
OpenCVE Enrichment