Impact
The vulnerability in Oracle Flow Manufacturing’s Internal Operations component allows a low‑privileged attacker who can access the system over HTTP to carry out unauthorized update, insert, or delete operations, and read a subset of data. The flaw is caused by insufficient access control (CWE‑284) and a cross‑site request forgery vulnerability (CWE‑352). Successful exploitation results in confidentiality and integrity compromise of application data and requires human interaction from a user other than the attacker, making the attack not fully automated.
Affected Systems
Oracle Flow Manufacturing, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 signals moderate severity. The EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires network access over HTTP, low authentication and privilege, and depends on user interaction, which limits automated attacks. Because the flaw includes a scope change, an exploit could enable unauthorized data operations within Flow Manufacturing and potentially impact other Oracle products that integrate with the platform.
OpenCVE Enrichment