Impact
A vulnerability in Oracle Bills of Material allows a low‑privileged attacker who can reach the application through an HTTP connection to compromise the system. The flaw enables a successful attacker to achieve full takeover of Oracle Bills of Material, affecting confidentiality, integrity, and availability. The weakness is consistent with an exploitation of improper privilege escalation or improper access control.
Affected Systems
Oracle Bills of Material in Oracle E‑Business Suite platforms, specifically Oracle Corporation’s Oracle Bills of Material product, is affected for releases between 12.2.3 and 12.2.15 inclusive. These deployments typically expose an HTTP interface that an external attacker can reach over the network.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.0 indicates a high‑severity risk, but the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting low likelihood of exploitation in the wild. The attack requires network access via HTTP, a low privileged attacker, and user interaction—indicating a social‑engineering component, but the low authentication requirement and remote nature lower the barriers to entry.
OpenCVE Enrichment