Impact
The flaw in Oracle Customers Online, part of Oracle E‑Business Suite, allows a low‑privileged attacker with network access over HTTP to create, delete, or alter critical data, or to read all data accessible through the application. The vulnerability is classified as an improper access control (CWE‑284) and is rated CVSS 3.1 with a base score of 8.1, indicating substantial confidentiality and integrity impacts while availability remains unaffected.
Affected Systems
Affected versions are Oracle E‑Business Suite 12.2.3 through 12.2.15 within the Customers Online application’s Internal Operations component. The product is widely used by enterprises that rely on this suite for e‑commerce and online transactions.
Risk and Exploitability
The EPSS score of less than 1% suggests that the vulnerability is not yet widely leveraged in the wild, and it is not listed in CISA’s KEV catalog. Nevertheless, because the flaw is easily exploitable via a direct HTTP request to internal endpoints that lack proper authorization checks, the potential for unauthorized data manipulation remains high. The low complexity and low privileges required elevate the risk for organizations that expose Customers Online to the network.
OpenCVE Enrichment