Impact
An Oracle Receivables vulnerability in the Internal Operations component allows an attacker who already has high‑privileged credentials and network access over HTTP to compromise the application. Exploitation can grant the attacker full control over the system, affecting confidentiality, integrity, and availability. The weakness is tied to improper privilege enforcement, consistent with CWE‑284 and CWE‑285.
Affected Systems
Oracle Receivables versions 12.2.3 through 12.2.15 from Oracle Corporation are affected.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.2 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires network‑based access to the HTTP service with high‑privileged credentials; once accessed, the attacker can bypass privilege checks and gain uncontrolled access to the application, enabling a full takeover.
OpenCVE Enrichment