Impact
The Oracle iReceivables product contains an easily exploitable flaw in the AR Web Utilities that allows a low privileged attacker who can reach the server via HTTP to create, delete, or modify critical data. Successful exploitation leads to confidentiality and integrity breaches, allowing unauthorized or complete access to all iReceivables data.
Affected Systems
Oracle iReceivables versions from 12.2.3 through 12.2.15 are impacted. The affected component is the AR Web Utilities of the Oracle E‑Business Suite.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity with both confidentiality and integrity impacts. The EPSS score of less than 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based over HTTP, requiring only low privileges to achieve significant data disruption.
OpenCVE Enrichment