Impact
This vulnerability is an authorization bypass that allows an attacker with only a low‑privileged account and network access to the Oracle Risk Management HTTP service to create, modify, delete, and read data that should be protected. The flaw results in a high confidentiality and integrity impact, reflected in the CVSS 3.1 base score of 8.1. It does not provide a path for remote code execution or denial of service, but it effectively removes all access controls for the affected data.
Affected Systems
Oracle Corporation’s Oracle Risk Management component of Oracle E‑Business Suite is affected. All supported releases from 12.2.3 through 12.2.15 contain the flaw. Users should verify the minor release they are running and contact Oracle for the appropriate fix or upgrade path.
Risk and Exploitability
The high CVSS score indicates a severe problem, and the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers need only remote HTTP connectivity and a legitimate but low‑privileged user credential to exploit the defect, giving them the ability to read all accessible data and modify or delete any critical information. Due to the clear impact on confidentiality and integrity, the flaw should be treated as a high‑risk issue that can be leveraged to compromise entire data sets within the susceptible application.
OpenCVE Enrichment