Impact
A vulnerability within Oracle Bills of Material allows a low‑privileged attacker who can reach the application through an unsecured HTTP interface to compromise the system. The flaw permits the attacker to gain full control over the Bills of Material service, which impacts confidentiality, integrity, and availability. This weakness corresponds to improper privilege escalation or access control (CWE-284).
Affected Systems
Oracle Bills of Material in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. These deployments typically expose an HTTP interface that an external attacker can reach over the network.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.0 indicates a high‑severity risk, but the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low likelihood of exploitation in the wild. The likely attack vector is via HTTP network access coupled with a social‑engineering component, as a user other than the attacker must assist to complete the attack. Low authentication requirements and remote exploitation lower barriers to entry, though user interaction is required.
OpenCVE Enrichment