Impact
The flaw exists in the Oracle Interaction Blending component of Oracle E-Business Suite, where a high-privileged attacker who can reach the RMI interface from the network can exploit a difficult-to-exploit weakness to perform unauthorized updates, inserts, or deletes, read restricted data, and trigger a partial denial of service. The vulnerability does not provide remote code execution but enables modification of application data and availability impact, as reflected by a CVSS 3.1 score of 4.1. Based solely on the description, it is inferred that the attack vector is via the RMI network channel and requires the attacker to possess high privileges on the host or the ability to act as an authenticated user.
Affected Systems
Affected products are Oracle Corporation’s Oracle Interaction Blending for Oracle E-Business Suite, in the supported versions 12.2.3 through 12.2.15. Users running any of these releases should verify their product version against this range.
Risk and Exploitability
The CVSS score and the EPSS score of less than 1 % indicate a low but present risk; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a network-connected RMI service and a high-privileged attacker, suggesting that while the attack surface is limited, sufficient internal access would let an attacker gain unauthorized data control and achieve a partial denial of service.
OpenCVE Enrichment