Impact
Oracle Price Protection is affected by a low‑privilege vulnerability that permits attackers who have local logon to the host to create, delete, or alter critical data. The flaw also enables unauthorized reading of all data the product can access, resulting in confidentiality and integrity loss. This is considered a privilege‑escalation defect through insecure access control.
Affected Systems
The vulnerability impacts Oracle Corporation’s Oracle Price Protection component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. Any installation of these releases that executes the Internal Operations component is at risk.
Risk and Exploitability
The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) yields a Base Score of 8.4, indicating high severity with confidentiality and integrity impacts. The EPSS score is below 1 %, so exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. The attacker requires local access; however, the scope change flag means successful exploitation could affect other Oracle products on the same infrastructure.
OpenCVE Enrichment