Impact
A flaw in the Inventory Optimization user interface permits an attacker who has a low‑privileged account and network reach to send specially crafted HTTP requests that can cause a partial denial of service. The weakness is a flaw in resource handling (CWE‑400) and is limited to availability; confidentiality and integrity are not affected.
Affected Systems
Oracle Inventory Optimization versions 12.2.3 through 12.2.15, specifically the User Interface component, are affected. Systems that expose this web UI to network traffic are at risk, while installations that have the UI isolated or disabled are not impacted.
Risk and Exploitability
The CVSS base score of 3.1 and an EPSS score of less than 1 % suggest a low likelihood of real‑world exploitation. The attack requires network connectivity to the UI and a low‑privileged account, making it hard to achieve. The resulting partial denial of service may degrade service continuity but is unlikely to cause immediate critical disruption.
OpenCVE Enrichment