Impact
The vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management within Oracle E‑Business Suite. A high‑privileged attacker who can reach the application over HTTP can exploit the flaw, leading to a full takeover of the Order Management subsystem. Successful exploitation compromises confidentiality, integrity, and availability, effectively allowing an attacker to control the entire Order Management system.
Affected Systems
Oracle Corporation’s Oracle Order Management product is affected. All supported releases from version 12.2.3 through 12.2.15 of the Oracle E‑Business Suite are vulnerable and remain susceptible until a fix is applied.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates high severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The flaw is network‑accessible over HTTP, requiring only high‑privileged credentials, and is not yet listed in the CISA KEV catalog. Despite the low EPSS, the potential for full system compromise warrants proactive remediation.
OpenCVE Enrichment