Impact
An Oracle Cost Management vulnerability allows a low‑privileged attacker with network access via HTTP to gain unauthorized control over critical data, enabling creation, deletion, or modification of records. The flaw can thus lead to significant compromise of confidentiality and integrity of all Oracle Cost Management accessible data, without affecting availability.
Affected Systems
Oracle Cost Management (part of Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are affected. All installations using these versions are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only low‑privilege access to the HTTP interface, which is typically reachable over the network. Once accessed, an attacker can authenticate with minimal privileges and exercise full data‑manipulation rights due to the underlying access‑control weakness.
OpenCVE Enrichment