Impact
A flaw in Oracle Sales Offline allows a low‑privileged network attacker with HTTP access to create, delete or modify data that the application considers critical, or to obtain full read access to all data handled by the application. The weakness grants high confidentiality and integrity compromise, allowing an attacker to undermine the integrity of business records and the confidentiality of sensitive information held by Oracle Sales Offline. No availability impact is reported.
Affected Systems
Oracle Sales Offline component of Oracle E-Business Suite, versions 12.2.3 through 12.2.15. These are supported releases of the Oracle Sales Offline application.
Risk and Exploitability
The CVSS score of 8.1 signals a high severity, and the EPSS score of under 1% suggests exploitation is not yet widespread but possible. The vulnerability is not listed in CISA KEV, but its ability to be exploited remotely via HTTP and the need for low privileges imply it could be leveraged by attackers with limited network access. An attacker can trigger the flaw by sending specially crafted HTTP requests to the application, thereby causing unauthorized data changes or readings. Based on the description, the likely attack vector is a remote network‑based HTTP request to an internal operations endpoint of the application.
OpenCVE Enrichment