Impact
The vulnerability arises in the Claim LOV component of Oracle Trade Management and allows an attacker with low privileges and network access through HTTP to create, delete, or modify critical data. The flaw can also provide unauthorized access to all data that a normal user could access, thereby compromising data confidentiality and integrity.
Affected Systems
Oracle Corporation’s Oracle Trade Management product of Oracle E‑Business Suite. Affected versions are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity flaw and the EPSS score of less than 1% suggests a low probability of exploitation, though the vulnerability is listed as not currently tracked by CISA’s KEV catalog. The attack vector is inferred to be network‑based HTTP traffic, requiring only low user privileges to succeed.
OpenCVE Enrichment