Impact
The Oracle Customer Support product of Oracle E‑Business Suite contains a vulnerability in the Update Service Request component that allows a low‑privileged attacker with network access over HTTP to create, modify, or delete critical data or gain full access to all data stored in Oracle Customer Support. The flaw is associated with information exposure, insufficient access control, and potential privilege escalation. This results in significant confidentiality and integrity compromise, as unauthorized users can perform privileged actions without proper authentication.
Affected Systems
The issue affects Oracle Customer Support versions from 12.2.3 through 12.2.15, which are part of Oracle E‑Business Suite. Users running these releases should verify whether they are using the Update Service Request component and consider the impact on their environment.
Risk and Exploitability
The CVSS vector indicates an attack from the network with low complexity and low privileges, suggesting the vulnerability can be exploited by anyone with basic network access to the service endpoint. The EPSS score is less than 1%, indicating a very low current exploitation probability. Since the vulnerability is not listed in the CISA KEV catalog, it is inferred that active exploitation may not be widely reported. It is also inferred that the flaw could be present on many on‑premises deployments that expose the Update Service Request service to external networks. Nonetheless organisations that expose Oracle Customer Support to external networks or manage it in a shared environment must treat this as a high risk, as the breach allows attackers to read, write, or delete sensitive data without proper authorization.
OpenCVE Enrichment