Impact
A flaw in the Internal Operations component of Oracle Public Sector Financials allows an attacker with a low‑privileged account and network access via HTTP to modify, insert, or delete data. The vulnerability does not directly compromise confidentiality or availability; it grants unauthorized data manipulation with an integrity impact reflected in the CVSS base score of 3.1.
Affected Systems
Oracle Public Sector Financials versions 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are vulnerable. The issue exists when this package is deployed and accessed over HTTP.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged account and HTTP network access; the description notes it is difficult to exploit, implying that a successful attack would entail careful enumeration of the application’s internal operations and possibly bypassing authentication controls.
OpenCVE Enrichment