Impact
A flaw in Oracle Learning Management permits a network attacker with low privileges, using HTTP, to gain unauthorized create, delete or modify rights over critical data. The vulnerability requires the victim to perform a separate action, indicating user interaction is needed. A successful exploit would compromise the confidentiality and integrity of all data stored in the Learning Management system, while availability remains unaffected. The weakness involves an insecure redirect component (CWE‑601) in addition to improper authorization (CWE‑284).
Affected Systems
Products affected include Oracle Learning Management within Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. These versions expose an internal operations component that is vulnerable to the described attack. Versions beyond 12.2.15 are not listed as affected, but administrators should verify patch status.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 signals a high impact, with a high confidentiality and integrity loss. The EPSS score is under 1%, implying the publicized exploitation probability is very low, yet the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires only basic network access and low privilege, making it attractive for attackers that can lure a victim to provide the required interaction.
OpenCVE Enrichment