Impact
An exposed HTTP endpoint in Oracle Supply Chain Trading Connector allows low‑privileged users to modify, insert, delete, or read data beyond their authorization, as well as trigger partial denial of service. The vulnerability stems from improper access control (CWE-284) and results in degradation of confidentiality, integrity, and availability of transaction data.
Affected Systems
Oracle Corporation’s Oracle Supply Chain Trading Connector for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. The flaw resides in the Collaboration History component and can be exploited by anyone with network connectivity to the Connector’s HTTP interface.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of real‑world exploitation. The vulnerability is not listed in CISA KEV, but an attacker with low privileges can achieve it remotely over HTTP with minimal effort if network access is not restricted.
OpenCVE Enrichment