Impact
A vulnerability in the Oracle iReceivables product of Oracle E‑Business Suite, specifically the AR Web Utilities component, allows a low‑privileged attacker with network access via HTTP to compromise the application. This flaw is easily exploitable and can lead to a full takeover of Oracle iReceivables, creating confidentiality, integrity and availability impacts as reflected by the CVSS 3.1 Base Score of 8.8.
Affected Systems
The affected product is Oracle iReceivables, with versions ranging from 12.2.3 to 12.2.15. The vulnerability is present in the AR Web Utilities component of these releases.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, but the high CVSS score suggests significant potential impact. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over HTTP, requiring only network connectivity and a low‑privileged attacker.
OpenCVE Enrichment