Impact
A flaw in the Search component of Oracle Knowledge Management permits an unauthenticated attacker who can reach the system over HTTP to perform unauthorized data modification and partial information disclosure. The weakness arises from improper authorization controls (CWE‑285), a cross‑site request forgery condition (CWE‑352), and open redirect usage (CWE‑601). Successful exploitation allows the attacker to update, insert or delete existing data as well as read confidential records, affecting both confidentiality and integrity.
Affected Systems
Oracle Knowledge Management within Oracle E‑Business Suite, versions 12.2.5 through 12.2.15, is affected. These releases expose the Search feature that is reachable over HTTP.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA KEV, meaning no confirmed active exploitation has been reported. Successful attacks require only network access to the application over HTTP and a second party providing user interaction, such as clicking a malicious link. Once a request is forged through the Search endpoint, the attacker gains unauthorized read and modify rights. The flaw’s scope change can potentially affect other components in the product suite.
OpenCVE Enrichment