Impact
The vulnerability enables a low privileged attacker with network access via HTTP to create, delete or modify critical data in Oracle Project Portfolio Analysis, potentially compromising data integrity and causing a partial denial of service, as described by its CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Affected Systems
The affected product is Oracle Project Portfolio Analysis from Oracle Corporation, versions 12.2.3 through 12.2.15. No further subcomponents are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.1, indicating moderate to high risk. The EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is likely over the network via HTTP and requires only low privileges, making it relatively easy to target within a compromised network.
OpenCVE Enrichment