Impact
The vulnerability is an instance of CWE‑284 (Improper Access Control) that lets a high‑privileged attacker with network access via HTTP create, delete or modify data and read all content in Oracle Citizen Interaction Center. The attacker can therefore compromise the confidentiality and integrity of critical data stored by the application.
Affected Systems
Oracle Citizen Interaction Center, part of Oracle E‑Business Suite, Internal Operations component. Supported releases affected are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 denotes moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires network connectivity to the HTTP interface and an attacker who already holds high‑level privileges, making the attack vector an external network attack that leverages improper access control.
OpenCVE Enrichment