Impact
The vulnerability is an improper access control flaw in the Fulfillment Engine of Oracle Service Fulfillment Manager that allows a high‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data, or obtain complete read access to all data exposed by the application. The flaw is reflected in a CVSS 3.1 base score of 8.7, indicating significant confidentiality and integrity impact, and its scope signals that an attacker could affect services beyond the Service Fulfillment Manager itself.
Affected Systems
Oracle Service Fulfillment Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are vulnerable. Deployments that expose the HTTP interface to an internal or external network are at risk, and the scope change means that any applications or services that rely on the Fulfillment Engine for data provisioning could also be adversely impacted.
Risk and Exploitability
The high CVSS score signals a serious threat, while the EPSS score of less than 1% suggests a low probability of active exploitation and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker accessing the exposed HTTP interface, which requires that the attacker already possess high‑privilege credentials or gains them via other means. No public exploit is currently known, but the scope change and privileged nature of the attack could result in extensive data compromise if the vulnerability is used.
OpenCVE Enrichment