Impact
The flaw is a privilege escalation vulnerability within the Internal Operations component of Oracle Order Entry. A high‑privileged attacker who has logged on locally to the server can perform unauthorized insert, update or delete operations on data handled by the application, causing loss of data integrity and enabling a partial denial of service of the service. No confidentiality impact is described. The weakness is classified under CWE‑269 (Improper Privilege Management) and CWE‑284 (Improper Access Control).
Affected Systems
Oracle Order Entry, part of Oracle E‑Business Suite, is affected for supported releases 12.2.3 through 12.2.15. The vulnerability resides in the Internal Operations component of these releases.
Risk and Exploitability
The CVSS v3.1 base score of 3.4 indicates a low overall risk, and the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is local and requires high privileges on the host, the likelihood of exploitation is low in well‑policed environments, but any privileged user who can log in locally remains at risk.
OpenCVE Enrichment