Impact
Oracle Process Manufacturing Systems in Oracle E-Business Suite is vulnerable in versions 12.2.3 through 12.2.15. The flaw allows an attacker who possesses low-level privileges and network access over HTTP to compromise the system, resulting in full control. This attack compromises confidentiality, integrity, and availability of the affected platform.
Affected Systems
The vulnerability affects Oracle Process Manufacturing Systems, a component of Oracle E-Business Suite. Versions 12.2.3, 12.2.4 up to 12.2.15 are impacted.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates a high severity. The EPSS score is below 1%, showing a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network access through HTTP and requires only low privilege, so while exploitation is technically easy, the real-world attack probability remains modest due to the specific network and privilege requirements.
OpenCVE Enrichment