Impact
The vulnerability resides in the Internal Operations component of Oracle Transportation Execution, part of Oracle E‑Business Suite. An attacker with low privileges who can reach the application via HTTP can exploit this flaw to compromise the system, resulting in full takeover of the application. The flaw is characterized by a CVSS 3.1 base score of 8.8, with severe confidentiality, integrity and availability impact, and an access vector of network, with low attack complexity and low privileges required.
Affected Systems
Affected versions are Oracle Transportation Execution 12.2.3 through 12.2.15, deployed under Oracle Corporation. The product in question is the Enterprise Business Suite’s transportation execution module, accessed over HTTP. Systems running any of the listed versions are vulnerable if they expose the internal operations component to the network.
Risk and Exploitability
The CVSS score of 8.8 places it in the critical range, whereas the EPSS score of less than 1 % indicates a low probability of observed exploitation, and it is not listed in the CISA KEV catalogue. Nevertheless, the low privilege attack requirement and accessible HTTP interface make the attack scenario straightforward for a motivated adversary. The description specifies that the flaw allows a low‑privileged attacker with network access, implying that authentication is not required for exploitation, and that the vulnerability resides in the internal operations functions, likely due to improper access control.
OpenCVE Enrichment