Impact
The vulnerability in Oracle Property Manager’s Internal Operations component allows a high‑privileged attacker with network access via HTTP to compromise the application. If successfully exploited, the attacker can gain complete control over Oracle Property Manager, resulting in total loss of confidentiality, integrity, and availability for that system. The weakness is an authorization failure (CWE‑284).
Affected Systems
Oracle Property Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high‑severity issue. The EPSS score is below one percent, suggesting limited exploitation activity to date, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) points to a remote, low‑complexity attack that requires the attacker to possess high‑level privileges, typically attainable through credential compromise or a pre‑existing privileged account. Consequently, the attack is likely to occur over HTTP from an externally reachable location, and mitigating network exposure combined with timely patching is the most effective defense.
OpenCVE Enrichment