Impact
A flaw in Oracle SDP Number Portability enables a local attacker with low‑privileged access to the infrastructure hosting the product to take over the application, resulting in full compromise of confidentiality, integrity, and availability. The vulnerability is exploitable without user interaction, and a successful compromise could allow an attacker to modify data, disrupt services, or pivot to other components of the Oracle E‑Business Suite.
Affected Systems
Oracle Corporation’s SDP Number Portability component of Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15 are affected. The vulnerability is within the Internal Operations component and may have broader implications for additional connected Products.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity with low attack complexity, local access and low privileges required, and no need for user interaction. The EPSS score is reported as < 1%, suggesting a very low yet non‑zero likelihood of exploitation in the wild. The exploit remains unlisted in CISA KEV. Local accounts on the target infrastructure constitute the attack surface; an attacker who can log into the host machine at a low privilege level can trigger the flaw, leading to takeover of SDP Number Portability and potentially impacting other modules. No public exploit code or zero‑day proof‑of‑concept is currently known.
OpenCVE Enrichment