Impact
A flaw in the Authorization component of Oracle Public Sector Financials (International) permits a low‑privilege attacker with network access over HTTP to bypass authorization controls. The flaw enables unauthorized inserts, updates, or deletes on the database, unauthorized reading of restricted data, and the ability to trigger a partial denial of service. This improper access control weakness directly impacts confidentiality, integrity, and availability as quantified by a CVSS 3.1 base score of 6.3.
Affected Systems
The vulnerability affects Oracle Public Sector Financials (International) versions 12.2.3 through 12.2.15, a component of Oracle E‑Business Suite commonly deployed by government entities managing public sector financial data.
Risk and Exploitability
With a CVSS 3.1 score of 6.3, the vulnerability is rated moderate severity. An attacker only needs low privileges and network access via HTTP, and no user interaction is required, making exploitation straightforward. The EPSS score is 0.00189, indicating a very low probability of exploitation, and the Oracle advisory describes the flaw as easily exploitable. The vulnerability is not listed in CISA’s KEV catalogue. Successful exploitation can lead to unauthorized data manipulation, data disclosure, and service interruption, threatening the trust and operational stability of impacted organizations.
OpenCVE Enrichment