Impact
Oracle Project Foundation suffers an improper access control flaw that allows any user with a local login to the underlying infrastructure to gain administrative control over the application. The vulnerability enables a low‑privileged attacker to subvert confidentiality, integrity and availability, ultimately leading to a full takeover of the system.
Affected Systems
The affected vendor is Oracle Corporation, specifically Oracle Project Foundation within Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 reflects high impact across all core security properties. The EPSS score of less than 1% indicates that, while exploitation is possible, it is currently considered uncommon. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires the attacker to already possess a local account with limited privileges; from there the flaw can be leveraged to elevate privileges and fully compromise the application.
OpenCVE Enrichment