Impact
The Oracle Sales Offline product of Oracle E‑Business Suite exposes an insecure HTTP endpoint that permits an attacker with only low privileges to create, delete, or modify critical data. The vulnerability also allows unrestricted read access to all data and the ability to cause a partial denial of service. This results in a combined impact on confidentiality, integrity, and availability, as reflected in the CVSS vector. The weakness occurs in the Internal Operations component without requiring local system access.
Affected Systems
Oracle Sales Offline, versions 12.2.3 through 12.2.15, are affected; all instances that expose the Internal Operations HTTP interface are vulnerable.
Risk and Exploitability
The CVSS 8.3 score demonstrates high severity, while the EPSS score of less than 1% indicates a very low, though not zero, probability of exploitation. Because the exploit is reachable via network over HTTP and does not require elevated privileges, it presents a significant risk to exposed installations. The vulnerability is not listed in CISA’s KEV catalog, but its impact warrants timely remediation.
OpenCVE Enrichment