Impact
A vulnerability in Oracle Internet Procurement Connector permits an attacker without authentication to send HTTP requests that can create, delete, or modify critical data. The flaw results in a loss of confidentiality and integrity for all data accessible through the connector, potentially allowing complete data compromise.
Affected Systems
The affected product is Oracle Internet Procurement Connector, available in Oracle E‑Business Suite versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 indicates a high level of risk, even though exploitation is described as difficult. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue has not been listed in CISA’s KEV catalog. However, the remote network access requirement and lack of authentication requirement mean that an adversary with network visibility could attempt exploitation. The vulnerability’s impact on confidentiality and integrity warrants immediate remediation once a patch is released.
OpenCVE Enrichment