Impact
A vulnerability exists in Oracle Public Sector Financials that allows an attacker with low privileged access to exploit the system over the network via HTTP. Successful exploitation can result in complete takeover of the application, compromising confidentiality, integrity, and availability of all data processed by the system.
Affected Systems
Oracle Public Sector Financials is affected for versions 12.2.3 through 12.2.15. The vulnerability is present in the Internal Operations component of the Oracle E‑Business Suite.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high severity flaw, while the EPSS score of less than 1 % indicates a low probability of prior exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack vector is network‑based and requires only low privilege, an attacker who can reach the HTTP endpoint can perform the exploit without user interaction or privileged credentials.
OpenCVE Enrichment