Impact
The vulnerability resides in the General Ledger Update Transform and Reports components of Oracle iSetup. It allows a low‑privilege attacker that can reach the service over HTTP to create, delete, or modify critical data and to access data that should be restricted. The flaw results in confidentiality and integrity violations, enabling unauthorized data handling without affecting availability.
Affected Systems
The affected product is Oracle iSetup, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. No other versions are impacted according to the available data.
Risk and Exploitability
Score 6.8 indicates medium severity, and EPSS below 1 % reflects a very low expected exploitation probability at this time. The flaw can be exercised remotely over the network using HTTP, requiring only low privileges. Although it does not affect availability, it permits unauthorized creation, deletion or modification of critical data, including full access to all data that Oracle iSetup can reach. The vulnerability is not listed in the CISA KEV catalog. Organizations with exposed Oracle iSetup instances should assess exposure and apply mitigations promptly.
OpenCVE Enrichment