Impact
The vulnerability in Oracle E‑Business Intelligence allows a low‑privileged attacker who can reach the system over HTTP to bypass normal access controls and create, delete, or modify critical data, giving the attacker full control over the information exposed by the product. The CVSS 3.1 base score of 8.1 reflects substantial confidentiality and integrity impacts without affecting availability.
Affected Systems
Affected vendors and products include Oracle Corporation’s Oracle E‑Business Intelligence component of the Oracle E‑Business Suite. The problematic versions range from 12.2.3 through 12.2.15. No other versions or components are listed as affected.
Risk and Exploitability
The EPSS score of less than 1% indicates that while the vulnerability exists, the likelihood of exploitation is currently low, and the vulnerability is not included in the CISA KEV catalog. However, the attack vector is inferred to be network‑based over unsecured HTTP, requiring only low privileges, which makes it potentially exploitable in environments that expose this interface to the internet or to untrusted networks. The combination of a high CVSS score and an easily exploitable attack surface places high risk on systems lacking the latest patch.
OpenCVE Enrichment