Impact
Oracle Assets in Oracle E‑Business Suite is vulnerable to a flaw that permits an attacker with high privileges and network access to an HTTP endpoint to take full control of the application. The vulnerability impacts confidentiality, integrity, and availability of the entire Assets component, allowing an adversary to compromise the system and potentially move laterally within the organization.
Affected Systems
The issue affects Oracle Assets versions 12.2.3 through 12.2.15, all supplied by Oracle Corporation as part of the Internal Operations component. No other vendor or product modules are listed.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high severity risk, while the EPSS value of less than 1 % suggests that overall exploitation likelihood is low at this time. The vulnerability is not presently included in the CISA KEV catalog. The likely attack vector is remote over HTTP; an attacker must be authenticated with high privileges, but does not require additional exploitation steps. Once accessed, the flaw allows takeover with no user interaction.
OpenCVE Enrichment