Impact
The vulnerability resides in the Oracle Supply Chain Trading Connector product, specifically the Collaboration History component. It allows an unauthenticated attacker with network access via HTTP to read critical data and perform unauthorized updates, insertions, or deletions on data handled by the connector. The CVSS 3.1 base score of 8.2 highlights a high confidentiality impact and a low integrity impact, while availability is not affected. The weakness originates from improper authentication in the HTTP interface.
Affected Systems
All installations of Oracle Supply Chain Trading Connector version 12.2.3 through 12.2.15 are vulnerable. The affected product is the connector component, and no other vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, but the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability can be reached remotely over HTTP without authentication, implying that an attacker can compromise sensitive data. Although not listed in CISA’s KEV catalog, the high confidentiality impact warrants prompt remediation to prevent data breach or alteration.
OpenCVE Enrichment