Impact
The Oracle Customers Online product of Oracle E‑Business Suite has a flaw in the Internal Operations component that allows an attacker with network access via HTTP to obtain low‑privileged access. Using this access, the attacker can create, delete, or modify critical data and, in worst case, gain complete access to all data available through Customers Online. The vulnerability directly impacts confidentiality and integrity, as reflected by its CVSS 3.1 score of 8.1 with high confidentiality and integrity effects.
Affected Systems
Oracle Customers Online, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. Systems running these releases are vulnerable if they expose the application to an external network over HTTP.
Risk and Exploitability
The CVSS base score of 8.1 denotes a moderate to high risk for confidentiality and integrity. The EPSS score of less than 1% indicates that current exploitation is unlikely, but the vulnerability can be leveraged once an attacker reaches the server via HTTP. The flaw is not listed in CISA KEV. Attackers would need only network reach to the application and can exploit the weakness without advanced privileges or special conditions.
OpenCVE Enrichment