Impact
A flaw in Oracle Assets, part of Oracle E‑Business Suite’s Internal Operations component, permits an attacker with low privileges and network access over HTTP to gain unauthorized capabilities. The vulnerability enables the attacker to delete, modify, or read critical data or all data accessible to Oracle Assets, causing loss of confidentiality and integrity of the asset information.
Affected Systems
Oracle Corporation’s Oracle Assets product for Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, is impacted.
Risk and Exploitability
The CVSS 3.1 score of 8.1 indicates a serious security risk, while the low EPSS score (<1%) suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attack would likely be performed over a public or internal network via standard HTTP requests, exploiting insufficient privilege checks in the Internal Operations interface.
OpenCVE Enrichment