Impact
This vulnerability exists in the Oracle Quoting component of Oracle E‑Business Suite, specifically within its Internal Operations module. It allows an attacker who has low privileges but can reach the system over HTTP to compromise the Quoting instance, potentially taking full control of the application. The CVSS v3.1 score of 7.5 reflects severe impacts on confidentiality, integrity, and availability, indicating that compromised data and services could be exposed, altered, or disrupted.
Affected Systems
Oracle Corporation’s Oracle Quoting product for Oracle E‑Business Suite is affected. Supported versions ranging from 12.2.3 to 12.2.15 are impacted. Only these versions are known to be vulnerable; newer releases beyond 12.2.15 are not listed as affected.
Risk and Exploitability
With a network‑based attack vector over HTTP inferred from the description, exploitation requires a low‑privilege user to submit a crafted request to the vulnerable endpoint. The difficulty of exploitation is noted, yet the potential impact is high. The EPSS score of less than 1% indicates that exploit attempts are currently rare, and the vulnerability is not recorded in CISA’s KEV catalog. However, due to the severe impact, the risk remains significant for exposed systems.
OpenCVE Enrichment