Impact
Oracle Demantra Demand Management suffers from an improper access control flaw that allows a low‑privileged attacker who can reach the system via HTTP to gain unrestricted control over the application. The vulnerability is classified as CWE‑284 and, if successfully exploited, can compromise confidentiality, integrity, and availability, effectively enabling a full remote takeover of the Demantra instance.
Affected Systems
The flaw affects Oracle Demantra Demand Management, part of Oracle Supply Chain Management, for versions 12.2.3 through 12.2.15. These releases are currently supported by Oracle and are listed as vulnerable to this issue.
Risk and Exploitability
The CVSS 3.1 base score is 9.9, reflecting a high‑severity condition with availability impacts. The EPSS score is below 1 %, indicating that widespread exploitation has not been observed, and the vulnerability is not yet included in CISA’s KEV catalog. The flaw is considered easily exploitable; an attacker with network access to the HTTP interface can exploit it remotely without authentication or user interaction, making the risk high for externally exposed deployments.
OpenCVE Enrichment