Impact
An unauthenticated attacker who can reach the physical communication segment of the hardware running Oracle Production Scheduling can exploit a missing authorization flaw in the Internal Operations component to take over the system. The vulnerability is considered difficult to exploit and is reflected in a CVSS 3.1 Base Score of 7.1, indicating high severity with full impact on confidentiality, integrity and availability. The weakness primarily stems from inadequate authentication controls over interfaces that can be accessed via the physical communication link. Based on the description, the missing authorization flaw is inferred from the stated lack of authenticated requirement and the need for physical access.
Affected Systems
The affected product is Oracle Production Scheduling, part of Oracle E‑Business Suite, with vulnerable releases spanning versions 12.2.3 through 12.2.15. All systems running these releases are exposed to the flaw, regardless of operating system or deployment environment.
Risk and Exploitability
The attack requires physical access to the communication segment and human interaction from a person not the attacker. Although the EPSS score is reported as < 1%, implying a low probability of exploitation on a broad scale, the CVSS score indicates that a successful exploit would result in a full system takeover. The vulnerability is not listed in CISA’s KEV catalog, and the vendor has not yet provided an official patch; however the risk to environments that allow such physical access remains significant.
OpenCVE Enrichment