Impact
A low severity vulnerability exists in the Definition component of Oracle E-Business Intelligence, allowing a high‑privileged attacker with network access over HTTP to modify, insert or delete accessible data. The weakness primarily impacts data integrity and requires the attacker to have high privileges and a human actor providing interaction, indicating that the attacker cannot fully execute the exploit alone.
Affected Systems
Oracle E-Business Intelligence, part of Oracle E-Business Suite, is affected for versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score of 2.0 and EPSS score below 1% reflect a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would proceed over HTTP, targeting the Definition component, and gains unauthorized data modification only after a user interaction by someone other than the attacker. The risk is therefore limited to environments where the software is exposed to network traffic and where privileged users or compromised accounts may be present.
OpenCVE Enrichment