Impact
Oracle Application Object Library for Oracle E‑Business Suite contains a flaw that allows a low‑privilege attacker with network access over HTTPS to gain higher privileges and then create, delete, or modify critical data. The vulnerability also grants an attacker unauthorized access to all data that the library exposes, and the flaw changes attack scope, potentially affecting additional components. This Access Control (CWE‑284) flaw is measured by a CVSS 3.1 score of 9.6, indicating a high confidential‑and‑integrity impact.
Affected Systems
Oracle Application Object Library, Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The high CVSS score and the fact that HTTPS means that any user with low privilege who can reach the exposed service could exploit the flaw. The EPSS score is so current exploitation activity is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the scope‑changing nature of the vulnerability provides the potential for significant impact beyond the immediate component.
OpenCVE Enrichment