Impact
The vulnerability resides in the Internal Operations component of Oracle Cost Management and permits a low‑privileged attacker with network access over HTTP to compromise the application. An attacker can create, delete, or modify data and gain full access to all data that the application exposes. The impact is significant confidentiality and integrity loss, while availability is not directly affected. The weakness aligns with improper access control and input validation issues, as the application fails to restrict unauthorized operations to privileged users.
Affected Systems
Oracle Cost Management for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are installed in many enterprise environments where the application is accessed via web interfaces. Users of these products must verify their deployed version against the listed range.
Risk and Exploitability
The CVSS 3.1 score of 6.8 indicates a moderate severity with high confidentiality and integrity impact. The EPSS score of less than 1 % reveals that exploitation is currently considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. However, because an attacker only needs low privileges and network reachability to HTTP, the attack vector is convenient for internal threat actors or compromised accounts. Successful exploitation can lead to unauthorized data changes or disclosure of all applications data, compromising regulatory compliance and audit controls.
OpenCVE Enrichment