Impact
An internally detectable flaw in Oracle Pasta, a component of Oracle E‑Business Suite, allows a high‑privileged user who has logged on to the host where Pasta runs to exploit the application and fully compromise it. The successful exploitation results in the attacker taking control of Pasta, thereby exposing or manipulating sensitive business data, bypassing controls, and potentially disrupting critical services.
Affected Systems
The vulnerability affects Oracle Corporation’s Pasta product within Oracle E‑Business Suite, specifically the Internal Operations module. Supported versions that are impacted are 12.2.3 through 12.2.15. No other vendors or versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.7 indicates moderate severity with high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests exploitation is unlikely but still possible, especially to users with local system access. The vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation at this time. The attack vector is inferred to be local (AV:L) and requires an attacker to have high‑privilege credentials on the underlying host; once achieved, the exploit can be executed with no user interaction (UI:N).
OpenCVE Enrichment