Impact
The vulnerability in Oracle Service Fulfillment Manager’s Fulfillment Engine permits a low‑privileged attacker who can reach the service over HTTP to create, delete, or modify critical data, or to gain unauthorized access to all data stored by the application. This results in substantial confidentiality and integrity loss.
Affected Systems
Oracle Service Fulfillment Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The product is impacted when the component termed Fulfillment Engine is present.
Risk and Exploitability
The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is less than 1 %, so widespread exploitation is unlikely, and the vulnerability is not cataloged in CISA’s KEV list. Nevertheless, an attacker who can reach the HTTP interface with low privileges can exploit the flaw, requiring only normal network access and resulting in unauthorized creation or deletion of data. The vulnerability remains a significant risk for organizations that have left the service exposed to untrusted networks.
OpenCVE Enrichment