Impact
A flaw in the Cost Planning component of Oracle Cost Management provides improper access control. An attacker with high privileges who can reach the service over HTTP can create, delete or modify critical data. The compromise also allows the attacker to cause a partial denial of service, impacting the ability to perform some operations. The weakness results in confidentiality, integrity, and availability impacts as reflected in the CVSS 3.1 score.
Affected Systems
Oracle Corporation’s Oracle Cost Management, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The vulnerability specifically targets the Cost Planning component of this product.
Risk and Exploitability
The CVSS v3.1 score of 6.2 indicates moderate severity, with impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires an attacker to possess high‑privilege credentials within the network and to access the service over HTTP. Successful exploitation would enable the attacker to alter critical data or partially disrupt service availability.
OpenCVE Enrichment