Impact
The Oracle Quality flaw allows a user with existing high‑privilege credentials to send crafted HTTP requests and gain full read, write, or delete control over any data that account can access. Because the vulnerability changes the component’s scope, the compromise can also reach other Oracle E‑Business Suite components that depend on Oracle Quality, amplifying the confidentiality, integrity, and availability damage. The weakness aligns with CWE‑269 (Broken Access Control) and CWE‑284 (Authentication Bypass).
Affected Systems
Oracle Quality, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. All installations within this range should be verified for the presence of the flaw and corrected promptly.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates high severity across confidentiality, integrity and availability, while the EPSS score of less than 1% suggests a low current probability of widespread exploitation. The vulnerability is not listed in CISA KEV. An attacker with network access to the exposed HTTP interface, and an account with high privileges, can exploit the flaw by sending specially crafted requests. The scope change increases the potential impact to additional Oracle components.
OpenCVE Enrichment