Impact
The vulnerability occurs in the Create Item Instance component of Oracle Installed Base, which is part of Oracle E-Business Suite. An unauthenticated or low-privileged attacker who can reach the application over HTTP can trigger the flaw and obtain unauthorized read access to critical data, or perform unauthorized insert, update, or delete operations on the Oracle Installed Base database. The flaw is classed as a high-confidentiality and moderate-integrity impact, with a CVSS 3.1 base score of 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Affected Systems
Affected versions of Oracle Installed Base are 12.2.3 through 12.2.15. The flaw is present in all releases in that range and exposes the system to network attackers who can exploit the Create Item Instance functionality.
Risk and Exploitability
The intrinsic CVSS score of 7.1 reflects a significant risk, while the EPSS score of less than 1 % indicates that only a very small fraction of the total vulnerability space is currently being exploited. Because the vulnerability is not listed in CISA’s KEV catalog, it has not yet been identified on a large scale, but the attack vector is straightforward: an attacker can send a crafted HTTP request from any remote host to the vulnerable endpoint, and the low privilege requirement lowers the barrier to exploitation. The potential for data exfiltration or corruption makes this flaw a high-priority concern for any organization running the affected Oracle E-Business Suite components.
OpenCVE Enrichment