Impact
A vulnerability in Oracle Landed Cost Management allows a low privileged attacker who can reach the system over HTTP to compromise the application. Successful exploitation allows the attacker to create, delete, or modify critical data, or even gain unrestricted access to all data managed by the system. The flaw carries severe confidentiality and integrity impacts, as reflected in the CVSS 3.1 scoring of 8.1 with a network attack vector, low attack complexity, low privileges, and no user interaction.
Affected Systems
Oracle Landed Cost Management, part of Oracle E‑Business Suite (Internal Operations), is affected for all supported releases from 12.2.3 through 12.2.15. Users of these versions should verify their installed revision and apply any Oracle‑released fixes.
Risk and Exploitability
The high CVSS score indicates a serious threat, yet the EPSS calculation of less than 1% shows a low current likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but its availability and the fact that it can be triggered by a low‑privileged network user make it dangerous in environments where HTTP access is permitted without strong network segmentation or authentication controls. Attackers, once accessing the network, can exploit this flaw without requiring privileged credentials or interacting with a user to achieve persistent data loss or unauthorized disclosure.
OpenCVE Enrichment