Impact
Vulnerability in the Oracle Configure to Order product of Oracle E‑Business Suite (Supply to Order Workbench component) allows an attacker with low privileges who can reach the web interface over HTTP to gain unauthorized access to critical data or full access to all Configure to Order data. The flaw also changes the system scope, enabling the attacker to potentially impact additional Oracle E‑Business Suite components.
Affected Systems
Oracle Configure to Order within Oracle E‑Business Suite versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 classifies the weakness as high–severity, while an EPSS score of less than 1 % indicates a very low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network access over HTTP and low‑privilege credentials, and the scope change enables the attacker to obtain access to all Configure to Order data and potentially other Oracle E‑Business Suite components.
OpenCVE Enrichment