Impact
A vulnerability exists in the Create Item Instance component of Oracle Installed Base that allows a low‑privileged user who can reach the service over HTTP to create, delete, or modify critical data. The flaw is an access control weakness (CWE‑284) that can be exploited without user interaction, leading to unauthorized changes to or deletion of business data and compromising confidentiality and integrity of Oracle Installed Base.
Affected Systems
Oracle Corporation’s Oracle Installed Base in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. All data accessible within those applications can be targeted by an attacker who has network connectivity to the HTTP interface and only low‑privilege credentials.
Risk and Exploitability
With a CVSS 3.1 base score of 8.1, the vulnerability sits in the high severity range and has significant confidentiality and integrity impact. The EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. In order to exploit the flaw, an attacker only needs TCP/IP connectivity to the exposed HTTP endpoint and a low‑privilege account; no elevated permissions or local access are required.
OpenCVE Enrichment