Impact
Easily exploitable via HTTP when a low privileged user is present. The flaw allows an attacker to perform unauthorized insert, update, or delete operations, as well as read protected data, thereby impacting data integrity and confidentiality. The vulnerability requires human interaction by a person other than the attacker to complete the attack, so the full exploitation depends on user cooperation.
Affected Systems
Oracle Property Manager, part of Oracle E‑Business Suite internal operations, affected versions 12.2.3 through 12.2.15 are listed by Oracle as vulnerable. Only these releases have the flaw according to the CNA information.
Risk and Exploitability
With a CVSS 3.1 score of 5.4 the risk is moderate, the EPSS score of less than 1% indicates a very low probability of widespread exploitation, and the vulnerability is not presently listed in CISA KEV. The likely attack vector is an HTTP endpoint that permits low‑privileged users to submit requests that bypass authorization checks, requiring another user’s interaction to trigger the action.
OpenCVE Enrichment