Impact
Oracle Transportation Execution (Oracle E-Business Suite component Internal Operations) contains an access control flaw that allows an attacker with low privileges to modify, insert, or delete data and read restricted data. The weakness is triggered via an HTTP interface and requires user interaction from someone other than the attacker. The impact includes confidentiality and integrity compromise but does not affect availability.
Affected Systems
Affected products are Oracle Corporation’s Oracle Transportation Execution for versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 score of 5.4 indicates moderate risk. The very low EPSS score (<1%) and absence from CISA KEV suggest exploitation is unlikely in the wild. However, the vulnerability can be leveraged only after a successful attack involving a low‑privileged user and human interaction, making it a targeted, low‑impact attack vector.
OpenCVE Enrichment