Impact
A vulnerability in Oracle Loans allows a low‑privileged attacker who can reach the application over HTTP to create, delete or modify user data, or to read all data available to the Loans system. The impact includes significant confidentiality and integrity loss for critical data and potentially full access to the Loans database. This weakness aligns with improper access control deficiencies such as CWE‑284.
Affected Systems
Oracle Loans, version 12.2.3 through 12.2.15, part of Oracle E‑Business Suite Internal Operations. Administrators should verify which release they run and whether it matches the affected range.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, indicating high overall risk. The EPSS score is below 1%, suggesting a very low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote over the network via HTTP, and the attacker requires only low privileges on the networked interface to exploit this weakness. The existence of this flaw means that any exposed instance of Oracle Loans could be compromised, allowing unauthorized and privileged data access.
OpenCVE Enrichment