Impact
Oracle iSupport, part of Oracle E‑Business Suite, contains a vulnerability in its Internal Operations component that allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is difficult to exploit but, if successful, results in unauthorized creation, modification, or deletion of critical data, and grants full read access to all Oracle iSupport accessible data. The impact is on confidentiality and integrity.
Affected Systems
Oracle iSupport, part of Oracle E‑Business Suite, is affected in supported versions 12.2.3 through 12.2.15 inclusive. Administrators should verify if their environment runs any of these versions.
Risk and Exploitability
Security analysts should note that the CVSS base score of 7.4 indicates a high severity vulnerability that impacts confidentiality and integrity. The EPSS score of < 1% suggests exploitation is currently unlikely but possible. Although the vulnerability is not listed in CISA's KEV catalog, it can be exploited via an unauthenticated HTTP request to the Internal Operations component. An attacker with network access can trigger the flaw without credentials and potentially read, modify, or delete critical data, thereby compromising data confidentiality and integrity.
OpenCVE Enrichment