Impact
Oracle Inventory Management’s Internal Operations component contains a flaw that can be exploited by a high‑privileged user who can log onto the host where the application runs. Successful exploitation provides the attacker with the ability to take over the application, compromising confidentiality, integrity, and availability of inventory data and control functions. The weakness is the granting of elevation of privilege (CWE‑269).
Affected Systems
Oracle Inventory Management for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected.
Risk and Exploitability
The CVSS 3.1 Base Score of 6.4 indicates moderate severity. Attack requires local access and high privileges, which reduces the likelihood of exploitation. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so no current evidence of exploitation exists. Nevertheless, environments that already have high‑privileged local accounts standing in contact with the Oracle Inventory Management servers remain at risk.
OpenCVE Enrichment