Impact
Oracle General Ledger is vulnerable to a high‑privilege attack that can be carried out over HTTP. The flaw allows an attacker who can reach the system on the network to gain unauthorized read access to sensitive data as well as insert, update, or delete operations on ledger records. The vulnerability is categorized as a privilege escalation and unauthorized data modification attack, leading to potential loss of confidentiality and integrity for all data accessible through Oracle General Ledger.
Affected Systems
Oracle General Ledger, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The flaw exists in the Internal Operations component and may also impact other products within the suite due to a scope escalation.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 indicates significant potential impact. The EPSS score of <1% (about 0.003) indicates a very low but non‑zero probability of exploitation; this suggests the flaw is not widely observed but could still be targeted. The vulnerability is easily exploitable over the network via HTTP. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be remote over the network, requiring high privileges and no user interaction, which suggests that an attacker with network access can exploit the flaw directly.
OpenCVE Enrichment