Impact
Vulnerability: a difficult‑to‑exploit flaw in the Fulfillment Engine of Oracle Service Fulfillment Manager lets an attacker with low privilege and network connectivity over HTTP compromise the service. The weakness results from broken object level authorization (CWE‑269), allowing the attacker to execute functions beyond their intended permissions. Successful exploitation leads to full takeover, impacting confidentiality, integrity, and availability of the Service Fulfillment Manager.
Affected Systems
Oracle Service Fulfillment Manager in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. No other products or versions are listed.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high‑severity risk, yet the EPSS score of less than 1% suggests the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request from a low‑privileged user; local or elevated privileges are not required.
OpenCVE Enrichment