Impact
A flaw in Oracle Project Portfolio Analysis allows an attacker with low privileges but network access via HTTP to override access controls and create, modify, or delete critical data. This improper access control can compromise both confidentiality and integrity of all data the application protects. The weakness is classed as CWE‑284 and scored highly with a CVSS 3.1 base score of 8.1.
Affected Systems
The vulnerability affects Oracle Corporation’s Oracle Project Portfolio Analysis product of Oracle E‑Business Suite. Versions from 12.2.3 up to 12.2.15 are impacted.
Risk and Exploitability
The exploit can be achieved over the public network with minimal effort from a low‑privileged user, and it requires no special software beyond a web client. The likely attack vector is inferred to be HTTP requests originating from an external network, as the description mentions network access via HTTP. Although the EPSS score is reported as less than 1 % – indicating low current exploitation probability – the high CVSS score and lack of KEV listing do not diminish the importance of remediation, as an attacker could readily gain valuable data or disrupt operations once the flaw is exploited.
OpenCVE Enrichment