Impact
Vulnerability in Oracle Price Protection, part of Oracle E‑Business Suite Internal Operations, is a CWE‑284 flaw that permits a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data, or to read sensitive subset data, thereby compromising both confidentiality and integrity of the system.
Affected Systems
Affected are Oracle Price Protection versions 12.2.3 through 12.2.15. These are the only releases confirmed to contain the flaw, according to Oracle. The product is used by organizations running Oracle E‑Business Suite, so any user of those versions is at risk if not patched.
Risk and Exploitability
The CVSS 3.1 score of 7.1 denotes high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. Nevertheless, the vulnerability is listed in no KEV catalog, but its impact and the ease of exploitation warrant vigilance. Attackers would need only network connectivity to an exposed HTTP service and minimal privileges to leverage the flaw, so checking for exposure is critical.
OpenCVE Enrichment