Impact
Oracle SDP Number Portability in Oracle E‑Business Suite can be exploited by a low privileged user with network access via HTTP to create, delete, or modify critical data. Successful exploitation results in loss of confidentiality and integrity of all data stored in SDP Number Portability and allows the attacker full access to any accessible data.
Affected Systems
Oracle SDP Number Portability component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high impact, while the EPSS score of less than 1 % suggests low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. A remote attacker with low privileges can send an HTTP request to the vulnerable service and gain unauthorized creation, deletion, or modification rights—and potentially obtain full read access to all SDP Number Portability data.
OpenCVE Enrichment