Impact
The Oracle Cash Management product in Oracle E‑Business Suite contains an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data and to gain unauthorized access to all data that the application can access. This improper access control on internal operations allows actions that are normally restricted to higher privileged users, thereby compromising the confidentiality and integrity of the financial data used by the system.
Affected Systems
Oracle Cash Management versions 12.2.3 through 12.2.15 are affected. These versions are deployed within Oracle E‑Business Suite environments where internal operations are enabled, meaning that any instance running those versions without the latest patch is vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity with high confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting that exploitation has not yet been widely observed, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is straightforward—remote, unmediated access via HTTP—and requires only low pre‑existing privileges, making it an attractive target for attackers who can reach the affected services.
OpenCVE Enrichment