Impact
The vulnerability in Oracle Advanced Supply Chain Planning is a high‑privilege access flaw that can be exploited by an attacker who has network reach to the service via HTTP. Once the flaw is leveraged, the attacker can gain full control of the application, effectively taking it over. This is a CWE‑284 weakness, indicating a failure to restrict access to privileged resources. Successful exploitation compromises confidentiality, integrity, and availability, allowing the attacker to read, modify, or delete data and interrupt service operations.
Affected Systems
The affected product is Oracle Advanced Supply Chain Planning, part of Oracle E‑Business Suite, component Core. Vulnerable releases span versions 12.2.3 through 12.2.15. The issue is specific to Oracle Corporation’s implementation and is documented in the July 2026 CPU advisory.
Risk and Exploitability
The base CVSS score is 7.2, indicating a high severity. The EPSS score is below 1%, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network access to the HTTP interface and the ability to authenticate with high‑privilege credentials, implying that the threat is limited to environments where such access exists. If exploited, an attacker can achieve a full application takeover.
OpenCVE Enrichment