Impact
A flaw in the Search Integration Engine component of Oracle E-Business Suite Secure Enterprise Search allows an attacker with low privileges to modify, insert, or delete data and to read restricted data over HTTP. The weakness is an improper access control, classified as CWE‑284, that undermines data integrity and confidentiality without providing remote code execution.
Affected Systems
The issue affects Oracle E-Business Suite Secure Enterprise Search versions 12.2.3 through 12.2.15 from Oracle Corporation. Users operating these releases with the Search Integration Engine exposed to the network are susceptible to exploitation.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 reflects a moderate severity while the EPSS score of less than 1% indicates that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits. Attackers must possess a low‑privilege user account and be able to reach the service over HTTP; no special permissions beyond this are required. Successful exploitation can lead to unauthorized data manipulation and partial data disclosure, potentially disrupting business processes and corrupting business data.
OpenCVE Enrichment