Impact
The vulnerability is an improper access control flaw (CWE‑284) that allows a low‑privileged attacker with network access to the HTTP interface of Oracle Project Portfolio Analysis to create, delete, or alter critical data, and to read protected data. Based on the description, it is inferred that the attacker likely needs a low‑privileged user account, but the requirement for authentication is not explicitly stated. The impact is a compromise of confidentiality and integrity of project information.
Affected Systems
Oracle Corporation's Oracle Project Portfolio Analysis, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score of 7.1 indicates substantial impact. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation prevalence. Attackers need only network access to the HTTP service and a low‑privilege user account; it is inferred that no elevated rights are required, but the description does not explicitly state whether additional authentication is needed. Successful exploitation can lead to unauthorized modification or deletion of project data and unauthorized read access to sensitive data.
OpenCVE Enrichment