Impact
A vulnerability in Oracle Learning Management’s Internal Operations component, classified as CWE‑284 (Improper Authorization), allows an attacker with low privileges that can reach the system over HTTP to create, delete, or modify critical data. The flaw can lead to unauthorized access to or destruction of all Oracle Learning Management data, jeopardising confidentiality and integrity of the system’s information.
Affected Systems
Oracle Learning Management, part of Oracle E‑Business Suite, is affected for version ranges 12.2.3 through 12.2.15. The vulnerability applies to the Internal Operations component and is reached via HTTP from the network.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity with confidentiality and integrity impacts. The EPSS score of less than 1% suggests the risk of exploitation is low at present, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need network access to the Oracle Learning Management HTTP interface and low privileges; no advanced privileges or local access are required for the attack to succeed.
OpenCVE Enrichment