Impact
The Oracle Financials Common Country product of Oracle E‑Business Suite includes an Internal Operations component that is vulnerable to an improper authorization flaw. A low‑privileged attacker who can reach the component over HTTP can craft requests to create, delete, or modify critical data, effectively gaining unauthorized data access or complete control over all Country data. The weakness results in severe confidentiality and integrity impacts, aligning with CWE‑284.
Affected Systems
Oracle Corporation’s Oracle Financials Common Country, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are vulnerable. No patch or upgrade notice is included in the data, so installations within this range remain at risk until remedial action is applied.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high‑severity flaw that can be exploited remotely. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based HTTP access to the Internal Operations component, where a low‑privileged attacker can send crafted requests to gain unauthorized data access or manipulation.
OpenCVE Enrichment