Impact
An internal access control flaw in Oracle Production Scheduling allows a local attacker with high privileged logon to the host to perform unauthorized update, insert or delete operations against the application’s data. Because the flaw bypasses normal access checks, the attacker can modify production scheduling information and compromise the integrity of the data that drives the organization’s operations.
Affected Systems
The vulnerability affects Oracle Production Scheduling for Oracle E‑Business Suite, specifically the Internal Operations component. Versions ranging from 12.2.3 through 12.2.15 are vulnerable. Only systems running these affected versions on infrastructure where users have local high‑privileged access are at risk.
Risk and Exploitability
The CVSS 3.1 base score of 1.9 indicates a low severity effect limited to integrity. Exploitation is possible only if the attacker already has authenticated high‑privileged logon on the host where the application runs; the vector is local. EPSS is reported as less than 1 %, meaning exploit attempts are expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the threat exists only where local administrative access is present and the application’s internal access controls are misconfigured.
OpenCVE Enrichment