Impact
Oracle Sales Offline contains an improper access control flaw that lets a low‑privileged user with network access via HTTP execute privileged actions and ultimately takeover the application. The CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H reflects high impact on confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Sales Offline component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. The issue resides in the internal operations module of Sales Offline.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % and absence from CISA’s KEV catalog suggest a low current exploitation probability. An attacker would need only low‑privilege credentials and HTTP network access to the Sales Offline instance to launch the attack, after which full control over the application can be achieved.
OpenCVE Enrichment