Impact
Oracle TeleSales, part of Oracle E‑Business Suite, contains a flaw that lets an attacker who possesses only a low‑privilege account and has network reachability over HTTP read or alter data that should be protected. The vulnerability does not grant remote code execution or service disruption; it simply expands the attacker's read and write capabilities within the TeleSales application.
Affected Systems
Oracle TeleSales component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. Any instance exposed on a publicly reachable HTTP interface is susceptible.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity. An EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalogue. Exploitation requires network connectivity to the TeleSales HTTP endpoint and a low‑privilege user account; no additional administrative permissions are needed. The attack path does not provide privilege escalation beyond the low‑privilege layer, nor does it allow remote code execution.
OpenCVE Enrichment