Impact
The vulnerability allows an attacker with low privileges and network access via HTTP to exploit a missing access control check to update, insert, or delete data, read protected information, or cause a partial service outage. The flaw is identified in the BI Publisher Integration component of Oracle E‑Business Suite. Based on the description, the attacker does not need to elevate privileges beyond what is already available.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Concurrent Processing product for Enterprise Business Suite, specifically versions 12.2.3 through 12.2.15. The vulnerability is present in the BI Publisher Integration component of this product and is not limited to a single module.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 indicates moderate impact to confidentiality, integrity and availability. The EPSS score of less than 1% means it is unlikely to be exploited in the near future, and it is not listed in CISA’s KEV catalog. However, the attack vector is network-based (HTTP) and requires only low privileges, implying that an external attacker could abuse the flaw to gain partial access to confidential data or disrupt services unless the patch is applied.
OpenCVE Enrichment