Impact
The vulnerability is a difficult‑to‑exploit remote flaw in Oracle Quality that permits an attacker with low privileges but network access over HTTP to compromise the product. When successfully exploited, it allows full takeover of Oracle Quality, compromising confidentiality, integrity, and availability as reflected by the CVSS score.
Affected Systems
It affects Oracle Corporation’s Oracle Quality component of Oracle E‑Business Suite, specifically the Internal Operations module in versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 classifies this issue as high severity, yet the EPSS score of less than 1% indicates a very low probability of real exploitation, and the description notes it is difficult to exploit. Because the attack vector is network‑based over HTTP and requires only a low‑privilege attacker, organizations should treat systems exposed to the network as potentially vulnerable within the same subnet.
OpenCVE Enrichment