Impact
The vulnerability in Oracle Enterprise Asset Management allows a low‑privileged attacker with network access over HTTP to gain unauthorized write and read capabilities against certain data sets. The flaw is described as difficult to exploit, yet once exploited it permits the attacker to modify or delete records and read restricted information, leading to integrity and confidentiality breaches.
Affected Systems
Oracle Enterprise Asset Management within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
With a CVSS 3.1 base score of 4.2, the severity is moderate. The EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers would need network access to the HTTP interface and a low privilege account, and would likely exploit the application’s insufficient access controls.
OpenCVE Enrichment