Impact
The flaw lies in the Internal Operations component of Oracle Treasury and represents a CWE‑284 (Improper Access Control) weakness. A remote user with low‑privileged credentials who can reach the application over HTTP can use the vulnerability to create, delete, or modify critical data. The attack compromises confidentiality and integrity, allowing an attacker to gain complete access to data that should be restricted to authorized roles.
Affected Systems
Oracle Treasury, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are impacted. The vulnerability applies to all installations of these releases.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 marks this as high severity. The EPSS score is under 1%, indicating a low probability of widespread exploitation at present, and the flaw is not catalogued in CISA KEV. Exploitation requires only low‑privilege credentials and HTTP connectivity to the Treasury interface, making it readily exploitable in networks where the application is exposed.
OpenCVE Enrichment