Impact
A vulnerability in Oracle Production Scheduling allows a high‑privileged attacker who can reach the system over HTTP to compromise the product. The flaw permits the attacker to create, delete or modify critical data and to read authorized data, resulting in confidentiality and integrity loss for the affected system. The CVSS 3.1 vector shows a low confidentiality impact (C:L), a high integrity impact (I:H), and a change in scope (S:C), indicating that an attack might affect other Oracle products as well.
Affected Systems
Oracle Production Scheduling, part of Oracle E‑Business Suite, versions 12.2.3 to 12.2.15 are affected. The flaw is located in the Internal Operations component and may extend beyond production scheduling due to the scope change.
Risk and Exploitability
The CVSS base score of 6.6 classifies the vulnerability as moderate severity. An EPSS score of less than 1% indicates a low likelihood of exploitation. The attack requires high privileges and network access via HTTP, suggesting that threat actors would need to be privileged users or have compromised accounts, rather than external attackers. The product is not listed in the CISA KEV catalogue. Overall, while the short‑term risk is limited by the low exploitation probability, the potential impact on business data warrants timely remediation.
OpenCVE Enrichment