Impact
A vulnerability exists in the User Interface component of Oracle Production Scheduling, allowing a low‑privileged attacker with network access over HTTP to exploit the system and gain unauthorized access to critical data or the entire database. The flaw enables confidentiality compromise without impacting integrity or availability. The weakness reflects an improper access control risk, enabling the attacker to bypass authentication restrictions.
Affected Systems
Oracle Production Scheduling versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite are affected. These versions are delivered as part of Oracle's enterprise resource planning solution and are commonly deployed in manufacturing and production planning environments.
Risk and Exploitability
The CVSS 3.1 base score is 5.3, indicating moderate risk largely due to confidentiality impact. The EPSS score is below 1%, suggesting exploitation is currently rare or unobserved. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Attackers must initiate a network connection via HTTP and possess limited privileges; however, once compromised, they can access any data the affected user can see. Because the vector is remote and the exploit is considered difficult, precedence suggests monitoring for related activity but urgent patching is desirable if sensitive data is involved.
OpenCVE Enrichment