Impact
The vulnerability permits an attacker with limited privileges who can reach the system over HTTP to compromise the Oracle Advanced Pricing service, potentially leading to full control of pricing operations. The stated CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that the flaw has severe confidentiality, integrity, and availability impacts when successfully exploited.
Affected Systems
Oracle Advanced Pricing, a component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected. Any system running these releases and exposed to network traffic on HTTP is vulnerable.
Risk and Exploitability
With a CVSS base score of 8.8 the vulnerability is considered high risk. The EPSS score of less than 1 % suggests that exploitation is currently rare, and the product is not listed in the CISA KEV catalog. However, because the attack does not require user interaction and requires only low privileges, a vulnerable system that is reachable over the network can be compromised remotely, which elevates the overall threat level for exposed environments.
OpenCVE Enrichment