Impact
A vulnerability in Oracle Production Scheduling allows a high‑privileged attacker with network access via HTTP to update, insert, or delete data, read a subset of data, and cause a partial denial of service. The weakness involves improper access control, enabling the attacker to compromise confidentiality, integrity, and availability of the application in a limited way. The vulnerability is exploitable in supported versions 12.2.3 through 12.2.15.
Affected Systems
Oracle Corporation's Oracle Production Scheduling component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 Base Score is 4.7, indicating a medium impact. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated attacker with elevated privileges operating over the network using HTTP, who can directly manipulate application data and partially disrupt availability.
OpenCVE Enrichment