Impact
The Oracle Advanced Pricing component in E‑Business Suite contains a vulnerability that allows a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to critical data or to all accessible data. Successful exploitation also permits the attacker to perform update, insert or delete operations on that data. This weakness is a case of broken access control (CWE-284) and directly impacts confidentiality and integrity as reflected in its CVSS 3.1 base score of 7.1.
Affected Systems
Oracle Advanced Pricing for E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any deployment that includes the Pricing Installation component is at risk if not patched.
Risk and Exploitability
The CVSS rating of 7.1 indicates high severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the weakness over HTTP with minimal privileges, enabling them to compromise data confidentiality and integrity.
OpenCVE Enrichment