Impact
Oracle Advanced Pricing includes a vulnerability that allows a low‑privileged attacker who can reach the service over HTTP to compromise the application, gaining unauthorized access to critical data. Successful exploitation can result in full access to all data available through the Oracle Advanced Pricing component, as well as the ability to update, insert, or delete entries. The vulnerability’s status is noted as difficult to exploit, indicating a non‑trivial attack surface, but the impact to confidentiality and integrity is significant.
Affected Systems
The affected product is Oracle Advanced Pricing from Oracle Corporation, specifically versions 12.2.14 and 12.2.15 of the Pricing Installation component. Because the vulnerability is marked as changing scope, systems that rely on Oracle Advanced Pricing may also be impacted even if they are not directly exposed.
Risk and Exploitability
The base CVSS score is 7.1, indicating a high‑severity issue that primarily affects confidentiality and integrity. The EPSS score is currently below 1 %, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network access to the HTTP endpoint of Advanced Pricing and is possible for users with low privilege; however, the documented difficulty raises the attack complexity. The combined effect is a moderate threat that could have broader implications for other Oracle E‑Business Suite products due to the scope change.
OpenCVE Enrichment