Impact
The vulnerability in Oracle Advanced Collections allows a low‑privileged attacker with network access via HTTP to take full control of the component. Successful exploitation leads to a complete takeover, compromising the confidentiality, integrity and availability of the application. This is a form of improper access control (CWE‑284) and missing authentication (CWE‑306) that permits privilege escalation (CWE‑269) and unauthorized execution of privileged actions (CWE‑287).
Affected Systems
Oracle Corporation’s Oracle Advanced Collections product within Oracle E‑Business Suite, specifically the Internal Operations component, is affected. Versions 12.2.3 through 12.2.15 contain the flaw. Users running any of these releases should verify their installed version and consult Oracle’s security alert for the necessary update.
Risk and Exploitability
The vulnerability receives a CVSS 3.1 base score of 8.8, indicating high severity. The EPSS score of less than 1% shows that, while the flaw is easy to exploit, current exploitation activity remains low. It is not listed in CISA’s KEV catalog. The attack vector is via network‑accessible HTTP interfaces and requires only low privileges to succeed.
OpenCVE Enrichment