Impact
An improper access control flaw (CWE‑284) in the Oracle Process Manufacturing Product Development component allows a low‑privileged attacker who can reach the application over HTTP to create, delete, or modify critical data. Successful exploitation leads to confidentiality and integrity compromise of the data as well as the possibility of obtaining unrestricted view of all application data.
Affected Systems
Oracle Process Manufacturing Product Development within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, in the Internal Operations component is affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects a high impact on confidentiality and integrity. An EPSS score of less than 1 % indicates a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be carried out over the network by sending crafted HTTP requests; the attacker only needs low‑privilege network access.
OpenCVE Enrichment