Impact
Oracle Advanced Pricing is vulnerable to a network‑based flaw that permits an attacker with low network privileges to alter, delete, or create critical data records. The impact is severe, involving both confidentiality and integrity violations, as attackers can read or tamper with any data exposed by Oracle Advanced Pricing. The weakness stems from insufficient authorization checks, allowing unauthorized manipulation of the application state.
Affected Systems
The affected product is Oracle Advanced Pricing within Oracle E‑Business Suite. Supported versions 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS base score of 8.1 classifies this vulnerability as high severity, and the EPSS score indicates a very low probability of exploitation today, yet the flaw remains exploitable over HTTP without additional authentication. Although not listed in the CISA KEV catalog, the combination of network access and privileged actions requires immediate attention. Successful exploitation would provide attackers with unrestricted modification rights over all data accessible by Oracle Advanced Pricing.
OpenCVE Enrichment