Impact
Oracle Inventory Management has a low‑severity flaw that allows a high‑privileged user who can log on to the host to compromise the application and trigger a partial denial of service. The weakness – an improper error handling issue (CWE‑404) – can affect the Availability of the Inventory Management component alone, with no impact on data confidentiality or integrity.
Affected Systems
The flaw affects Oracle E‑Business Suite Oracle Inventory Management versions 12.2.3 through 12.2.15. It is local; the attacker must have privileged access on the infrastructure where the product runs.
Risk and Exploitability
The CVSS 3.1 base score of 1.9 reflects a low availability impact with a local access vector, high attack complexity, and high privileges required. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Only users who already possess privileged access could exploit this flaw, so the risk is confined to environments where such access exists.
OpenCVE Enrichment