Impact
A vulnerability in Oracle Installed Base’s Create Item Instance component allows an attacker with low privilege and network access via HTTP to read, update, insert, or delete data that should be protected, or to trigger a partial denial of service. If successfully exploited the attacker could modify application data, exfiltrate sensitive information, or disrupt service availability. The weakness is a failure of proper access control, allowing unauthorized operations on database records and causing limited interruption to service normality.
Affected Systems
Oracle E-Business Suite users running Oracle Installed Base versions from 12.2.4 through 12.2.15 are affected. The vulnerability is present only in the Create Item Instance component of these releases.
Risk and Exploitability
The CVSS 3.1 base score of 5.0 reflects moderate risk, with a low exploitation probability indicated by an EPSS score of less than 1%. The attack vector is likely network‑based over HTTP and requires a low‑privileged account. The vulnerability is not currently listed in the CISA KEV catalog. Due to the low surface and high access requirement, exploitation is considered difficult, but the potential for unauthorized data manipulation and service disruption warrants attention.
OpenCVE Enrichment