Impact
A vulnerability exists in the Oracle Complex Maintenance, Repair and Overhaul product, specifically within its Internal Operations component of Oracle E‑Business Suite. An unauthenticated attacker who can reach the application over HTTP can exploit a weakness that allows unauthorized reading of sensitive data as well as insertion, updating, or deletion of data available to the application. The flaw is an authorization failure (CWE‑284), resulting in high confidentiality impact and lower integrity impact, while availability is not directly affected.
Affected Systems
Oracle Complex Maintenance, Repair and Overhaul, a component of Oracle E‑Business Suite provided by Oracle Corporation, is affected for versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity with significant confidentiality loss. The EPSS score of <1% shows that active exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the product via unauthenticated HTTP requests over the network, which may also expand the attack’s scope to compromise additional Oracle products that share the same environment.
OpenCVE Enrichment