Impact
A vulnerability in the Oracle Process Manufacturing Logistics component permits a high‑privileged attacker who can reach the application over HTTP to compromise the system. The flaw enables the attacker to take full control of the component, resulting in complete loss of confidentiality, integrity, and availability of the application and potentially affecting additional products through a scope change. The weakness manifests as improper access control and weak privilege management.
Affected Systems
Oracle Process Manufacturing Logistics component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.0 indicates substantial severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The attack vector requires network access via HTTP, high privileges to initiate the exploit, and a difficult-to-exploit path (high attack complexity). Successful exploitation would grant the attacker full takeover of the component and expose data and processes.
OpenCVE Enrichment