Impact
A flaw in the Oracle Inventory Management Core Receiving component, identified as a missing access control weakness (CWE-284), allows an attacker with low privileges to use an HTTP interface to create, delete or modify critical data, or obtain complete access to all inventory information. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) shows that the vulnerability is exploitable over the network with minimal effort and produces full confidentiality and integrity compromise.
Affected Systems
Oracle Inventory Management for Oracle E‑Business Suite, Core Receiving component, versions 12.2.3 through 12.2.15, are affected.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, yet the EPSS score of less than 1% signals a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Attackers only need network access via HTTP and low‑privilege credentials; no elevated privileges are required. While exploitation is unlikely at present, the potential for serious data integrity and confidentiality damage warrants prompt action.
OpenCVE Enrichment