Impact
A flaw exists in Oracle Cost Management’s Inventory Costing component that allows an attacker who has network access via HTTP to exploit a high‑privilege access control weakness. Once leveraged, the attacker can fully take over the application, modify or exfiltrate cost data, and disrupt service operation. The vulnerability is identified as CWE‑284 (Broken Access Control). The CVSS 3.1 base score of 7.2 reflects moderate severity but indicates that the impact is comprehensive when successful.
Affected Systems
Affected systems are the Oracle Cost Management product within Oracle E‑Business Suite, specifically the Inventory Costing module. Versions 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS score of 7.2, combined with an EPSS score of less than 1%, suggests low exploitation probability in the wild, though the risk is heightened for environments that expose Cost Management over HTTP and maintain accounts with high privileges. The vulnerability is not listed in the CISA KEV catalog, so no confirmed widespread attacks are reported, but the potential impact warrants prompt remediation. The likely attack path involves an attacker using remote HTTP traffic to a Cost Management endpoint, leveraging their elevated credentials to bypass access controls and gain total control of the application.
OpenCVE Enrichment