Impact
A flaw in the Claim LOV component of Oracle Trade Management permits low‑privileged users, who can reach the system via HTTP, to create, delete, or modify critical data and to read data that should be restricted. The vulnerability is classified as an access control issue, reflected by CWE‑284, and results in significant confidentiality and integrity compromise as indicated by a CVSS v3.1 base score of 8.1.
Affected Systems
Oracle Corporation’s Oracle Trade Management product within Oracle E‑Business Suite is affected. The flaw applies to all supported versions from 12.2.3 through 12.2.15.
Risk and Exploitability
The relatively high CVSS score signals substantial risk, but the EPSS score of less than 1% suggests that, at present, exploitation attempts are unlikely. The vulnerability is not listed in CISA KEV. Attackers would require network access to the exposed HTTP interface and only low privileges, making the exploitation straightforward once containment controls are bypassed.
OpenCVE Enrichment