Impact
The vulnerability allows an attacker with low‑privileged network access via HTTP to take control of Oracle Customer Care. Exploitation results in full compromise with confidentiality, integrity and availability lost. The weakness pertains to improper access control, enabling an attacker to override authentication or authorization controls.
Affected Systems
Oracle Customer Care product of Oracle E‑Business Suite, component Internal Operations, versions 12.2.3 through 12.2.15 are affected. Any installation of these versions exposed to the network is at risk.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.8 indicates high severity. EPSS is below 1 %, meaning current exploitation likelihood is low but not zero. The vulnerability is not listed in CISA KEV catalog, but given the high impact, this high‑impact, low‑probability threat should still be treated as serious. Based on the description, it is inferred that the likely attack path would involve an attacker with low‑privileged HTTP access exploiting the access‑control flaw to gain control of the application. No mitigations beyond patching are described in the advisory.
OpenCVE Enrichment