Impact
A flaw in the Party Search UI of Oracle Trading Community allows an attacker who already possesses high‑privilege credentials and network access over HTTP to bypass proper access controls. This weakness can be leveraged to alter application state, exposing confidential data and disrupting service. The impact spans confidentiality, integrity, and availability, effectively granting the attacker full control of the platform.
Affected Systems
Oracle Trading Community product, versions 12.2.3 through 12.2.12, is affected. Users of these releases should confirm the exact version they are running to determine exposure.
Risk and Exploitability
The CVSS base score of 7.2 signals a high severity issue, yet the EPSS score of less than 1% indicates a low probability of current exploitation and the vulnerability is not listed in the CISA KEV catalog. Attackers would need high‑privilege credentials and HTTP access to the application, most likely within a trusted network. Successful exploitation of this vulnerability could lead to a full takeover of Oracle Trading Community.
OpenCVE Enrichment