Impact
This vulnerability resides in the Internal Operations component of Oracle Financials for the Americas. It permits an attacker who already has high‑level privileges within the network to exploit the application over HTTP, leading to full takeover of the application. The exploit can compromise confidentiality, integrity, and availability, as reflected by the CVSS base score of 7.2.
Affected Systems
Oracle Financials for the Americas, part of Oracle E‑Business Suite, vulnerable versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity with full impacts to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is currently rare, but the flaw remains readily exploitable via network HTTP traffic. The attack vector involves sending malicious requests to the Internal Operations component; the attacker must possess high privileges in the network to achieve compromise. As of the information provided, there no confirmed wild exploitation documented.
OpenCVE Enrichment