Impact
A vulnerability in Oracle E‑Business Intelligence allows an unauthenticated attacker with network access via HTTP to compromise the system, resulting in unauthorized update and delete operations as well as read access to a subset of data. The weakness involves improper authorization controls, limiting confidentiality and integrity but not availability. The CVSS 3.1 Base Score is 6.1, indicating a medium severity with medium confidence in the impact figures.
Affected Systems
The affected product is Oracle E‑Business Intelligence included in Oracle E‑Business Suite, specifically the Internal Operations component. Versions from 12.2.3 through 12.2.15 are impacted. Users running any of these releases are at risk if the software is exposed to HTTP traffic.
Risk and Exploitability
The attack vector requires an unauthenticated HTTP connection and human interaction from a non‑attacker, which limits the likelihood of successful exploitation. The CVSS 3.1 Base Score of 6.1 indicates medium confidentiality and integrity impact, and the vector shows a scope change (S:C), meaning this vulnerability in Oracle E‑Business Intelligence could also affect additional Oracle products. The EPSS score is less than 1 %, indicating a very low probability of immediate exploitation, and the vulnerability is not listed in KEV. Given the potential for data loss or modification, the risk remains significant for organizations that keep the exposed interfaces online.
OpenCVE Enrichment