Impact
Vulnerability in the Oracle Production Scheduling product (Internal Operations component) allows a low‑privileged user with local logon to the infrastructure to create, delete, modify, or read Oracle Production Scheduling data. The exploit requires user interaction but grants unauthorized access to critical data, resulting in confidentiality compromise (low impact) and heightened integrity impact (high).
Affected Systems
Oracle Production Scheduling from Oracle Corporation, versions 12.2.3 through 12.2.15, is affected. The product runs within Oracle E‑Business Suite and may impact additional products if exploited.
Risk and Exploitability
The CVSS 3.1 base score of 6.7 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local low‑privilege access and rely on a user other than themselves to perform the exploitation, making the attack path more constrained but still potentially dangerous for environments where local access is granted to many users. Organizations should evaluate the likelihood of local access being available to untrusted personnel and the sensitivity of the protected data before determining remediation urgency.
OpenCVE Enrichment