Impact
A flaw in Oracle Financials Common Modules allows an attacker with only low‑privilege network access over HTTP to create, delete, or modify critical data. The weakness is an authorization bypass (CWE‑284) where the system fails to enforce proper privilege checks, enabling unauthorized manipulation of or access to all module data.
Affected Systems
Oracle Corporation’s Oracle Financials Common Modules, supported versions 12.2.3 through 12.2.15, are affected. The vulnerability resides in the Common Components component of the Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. An attacker can exploit the vulnerability over the network via HTTP with only low-level privileges, enabling potential wide‑scale data compromise if not mitigated.
OpenCVE Enrichment