Impact
The vulnerability in Oracle Order Management’s Product Diagnostic Tools enables a low‑privileged attacker with HTTP network access to modify, delete, or read restricted data. By exploiting this flaw, an attacker can perform unauthorized updates, insertions, or deletions and gain read access to sensitive Oracle Order Management data without passing authentication or authorization checks, thereby compromising data integrity and confidentiality.
Affected Systems
Affected are Oracle Order Management versions 12.2.3 through 12.2.15 as part of Oracle E‑Business Suite. Deployments that expose the Product Diagnostic Tools component over HTTP are susceptible, and the flaw may indirectly affect additional related products due to a scope change.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates moderate risk, while the EPSS score of less than 1 % points to a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the scope expansion to other products increases potential impact. Successful exploitation requires an attacker with low‑level network access to the Product Diagnostic Tools via HTTP, allowing them to read, insert, update or delete data without proper authorization, thereby compromising data integrity and confidentiality.
OpenCVE Enrichment