Impact
A flaw in Oracle Process Manufacturing Systems allows an attacker with low privileges and simple network access over HTTP to create, delete, modify critical data and access all data handled by the system. The vulnerability is an improper access control flaw that leads to confidentiality and integrity violations. The impact allows full unauthorized control over system data.
Affected Systems
Oracle Process Manufacturing Systems versions 12.2.3 through 12.2.15 are affected. The flaw resides in the Internal Operations component of Oracle E‑Business Suite. Users running any of these releases should confirm their deployment version falls within the affected range.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, with network access required, low attack complexity, and low privilege needed. The EPSS score is below 1 % indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a low‑privileged user sending specially crafted HTTP requests to the Internal Operations module, bypassing normal access controls to create, delete, or modify critical data.
OpenCVE Enrichment