Impact
Oracle Warehouse Management in Oracle E‑Business Suite is vulnerable through the Internal Operations component, affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable, allowing a low‑privileged attacker with network access over HTTP to gain full control of the system, compromising confidentiality, integrity, and availability.
Affected Systems
The affected systems include Oracle Corporation’s Oracle Warehouse Management product, specifically the Internal Operations component in versions 12.2.3 to 12.2.15.
Risk and Exploitability
With a CVSS v3.1 score of 8.8, the vulnerability poses high risk. The EPSS score of <1% indicates a very low overall likelihood of exploitation at present, and it is not listed in CISA’s KEV catalog. The likely attack vector is through HTTP traffic, and the requirement for low‑privileged access suggests that network‑based exploitation could be straightforward for an attacker with any user credentials.
OpenCVE Enrichment