Impact
The vulnerability in Oracle E-Business Intelligence permits an attacker with high privileges and network access to create, delete, or modify critical data. This grants the attacker unauthorized control over the system’s data assets, leading to confidentiality and integrity breaches without affecting availability.
Affected Systems
Affected are Oracle E-Business Intelligence versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite. These are the only documented vulnerable releases. The issue is specific to the Internal Operations component of the product.
Risk and Exploitability
The CVSS 3.1 base score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation and it is not listed in CISA’s KEV catalog. The vulnerability is accessed over the network via HTTP, likely requiring attackers to have network connectivity to the affected system and, as inferred from the CVSS vector, likely requiring elevated authorization before exploitation. Likely, a compromise of a service account would permit full data manipulation within the scope of that account’s permissions.
OpenCVE Enrichment