Impact
The vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management. A high‑privileged attacker who can reach the application over HTTP may compromise the system and gain unauthorized access to critical data. The flaw is an Improper Access Control (CWE‑284) that lets the attacker elevate privileges to read, and potentially write, configuration and transactional data. Because the issue is in a core component, a successful exploit can also affect other Oracle E‑Business Suite products that share the same database or process environment.
Affected Systems
Oracle Order Management versions 12.2.3 through 12.2.15 are affected. The vulnerability is listed under the Oracle Corporation:Oracle Order Management product line and has no other vendor or product variants identified in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score of 6.8 reflects a moderate confidentiality impact, with a remote attack vector over HTTP requiring high privileges. The EPSS score is below 1 %, indicating a low probability of exploitation in the near term, and the vulnerability is not included in CISA KEV. However, because the exploit provides a path to full data access and can alter the scope to other applications, the risk to confidential information remains significant for organizations that have not applied the patch or otherwise restricted access to the diagnostic interface.
OpenCVE Enrichment