Impact
The vulnerability allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data in Oracle Complex Maintenance, Repair and Overhaul, resulting in unauthorized disclosure and tampering of all data accessible to the component; the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) reflects high impact on confidentiality and integrity.
Affected Systems
Oracle Complex Maintenance, Repair and Overhaul, part of Oracle E‑Business Suite’s Internal Operations module, is affected for versions 12.2.3 through 12.2.15 inclusive; this includes all deployments of the component within those released versions.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, while the EPSS score of less than 1 % suggests a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog; the attack can be carried out over the network via HTTP with only a low‑privileged account and no user interaction, making it relatively easy to exploit if the component is exposed.
OpenCVE Enrichment