Impact
This vulnerability exposes Oracle MES for Process Manufacturing to unauthenticated HTTP requests that can read and modify critical manufacturing data. The flaw allows an attacker to obtain confidential information with high confidentiality impact and to alter or delete data, resulting in integrity compromise. The CVSS 3.1 base score of 8.2 reflects these high impacts, while the attack maintains low complexity and requires no prior credentials.
Affected Systems
Oracle MES for Process Manufacturing, part of the Oracle E‑Business Suite, is affected in the 12.2.3 through 12.2.15 release line. The vulnerability resides in the Internal Operations component and applies to all installations that expose the MES web interface over HTTP.
Risk and Exploitability
Although the EPSS score is below 1 % indicating a low likelihood of exploitation at this time, the high CVSS score and lack of a KEV listing mean the risk should be taken seriously. The exploit requires an unauthenticated attacker to send crafted HTTP traffic, and an additional human interaction from a user other than the attacker is necessary to trigger the action. Successful attacks can result in unauthorized reads and writes to MES data and, due to the scope change, could also affect linked Oracle products.
OpenCVE Enrichment