Impact
A vulnerability in Oracle Lease and Finance Management, identified as a CWE‑284 improper access control flaw, allows an attacker with only low‑level credentials and network access over HTTP to perform unauthorized creation, deletion, or modification of critical data. The weakness grants the attacker the same authority as a legitimate user, exposing sensitive financial information to tampering or loss. The flaw does not permit denial of service but poses a significant confidentiality and integrity risk because data integrity can be compromised within the affected system.
Affected Systems
Oracle Lease and Finance Management (Oracle E‑Business Suite), versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity with serious confidentiality and integrity impacts. The EPSS score is below 1%, suggesting that active exploitation is currently rare, and it is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack via the HTTP interface using a low‑privileged user account. Successful exploitation would give the attacker broad unauthorized access to all data the application can reach.
OpenCVE Enrichment