Impact
The vulnerability exists in the Internal Operations component of Oracle Public Sector Financials. It results from multiple access‑control and authentication weaknesses (CWE-269, CWE-284, CWE-287, CWE-306) that allow a low‑privileged attacker with access to the HTTP interface to execute a difficult‑to‑exploit attack. Successful exploitation grants the attacker the ability to read, modify, delete sensitive financial records, disrupt services, and potentially elevate privileges within the organization.
Affected Systems
Affected products are Oracle Public Sector Financials from Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity with complete confidentiality, integrity and availability loss. The EPSS score of less than 1% suggests a low probability of real‑world exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. An attacker requires only network access to the HTTP interface and low privileges; no administrative credentials are necessary, making the attack surface moderate but the potential impact substantial if exploited.
OpenCVE Enrichment