Impact
Vulnerability in Oracle Service Contracts (Internal Operations component) permits an attacker with high privileged credentials and network access via HTTP to create, delete, or modify critical data. The flaw is a CWE-284 Improper Access Control, with a CVSS 3.1 base score of 5.7, driven by confidentiality and integrity impacts, and requires human interaction from a user other than the attacker to succeed. The effect is unauthorized alteration of data or complete access to all Oracle Service Contracts data accessible to the victim.
Affected Systems
The affected product is Oracle Service Contracts, part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are vulnerable. No other vendor or product is listed.
Risk and Exploitability
The only network attack vector is via HTTP (AV:N). Attackers must have high privileges (PR:H) and high complexity (AC:H). User interaction is required (UI:R) and the scope remains unchanged (S:U). The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation seen in the field, and the vulnerability is not listed in CISA's KEV catalog. Despite the low exploitation probability, the potential impact on data confidentiality and integrity makes the vulnerability significant for environments that rely on the Oracle Service Contracts product.
OpenCVE Enrichment