Impact
A low‑privileged attacker with network access to the Oracle Application Object Library can exploit a vulnerability that enables unauthorized update, insert, or delete operations on accessible data, as well as read a subset of that data and trigger a partial denial of service. The impact spans confidentiality, integrity, and availability, with a CVSS v3.1 base score of 6.3 indicating a moderate but significant risk to the exposed information and system function.
Affected Systems
Oracle Application Object Library, part of Oracle E‑Business Suite Core, is vulnerable in all supported releases from 12.2.3 through 12.2.15, as noted in the vendor’s advisory.
Risk and Exploitability
The attack vector is a network‑based HTTP connection that requires low privilege and no user interaction. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the moderate CVSS score and the potential for non‑trivial data compromise and service interruption warrant a timely remediation effort.
OpenCVE Enrichment