Impact
The vulnerability in Oracle Financials Common Modules allows a low‑privileged attacker with network access over HTTP to perform unauthorized creation, deletion, modification, and read operations on critical data. The flaw provides a breach of confidentiality and integrity without affecting availability. The vulnerability is an instance of improper access control, enabling attackers to manipulate or view data they should not be able to access.
Affected Systems
Oracle Corporation – Oracle Financials Common Modules (Oracle E‑Business Suite, Common Components). Versions from 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 base of 7.1, indicating a high impact on confidentiality and integrity. The EPSS score is below 1%, implying limited yet still possible exploitation. It is not included in CISA’s KEV catalog. The CVSS vector points to network attack, low authentication, and user interface absence, and the description indicates the attacker must be a low‑privileged user with HTTP access, suggesting that the exploit likely requires an application‑level authentication context or misconfigured access controls within the module.
OpenCVE Enrichment