Impact
The vulnerability resides in the Party Search UI component of Oracle Trading Community. An attacker with low privileges who can reach the application over HTTP can exploit the interface to create, delete, or modify critical data. Because the flaw allows unauthorized changes to data that is critical to the application, confidentiality and integrity are both severely impacted, with the attacker able to read or alter sensitive information without proper authorization.
Affected Systems
This issue affects Oracle Trading Community for Oracle E‑Business Suite versions 12.2.3 through 12.2.15. The product is delivered by Oracle Corporation under the Oracle Trading Community brand. No earlier or later releases are reported as vulnerable in the supplied information.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, indicating a high‑severity impact. The EPSS score is less than 1 %, so the likelihood of exploitation in the wild at the moment is low, and the vulnerability is not listed in CISA’s KEV catalog. The attack is achievable over a network using standard HTTP, requiring only low privilege credentials, and can lead to unauthorized data modification or deletion.
OpenCVE Enrichment