Impact
A low‑privileged attacker who can access the Oracle Advanced Benefits application over HTTP can exploit an access control weakness in the Affordable Care Act component. The flaw, identified as CWE‑269, CWE‑284, and CWE‑306, allows an attacker to bypass authentication and access privileged functionality, thereby compromising the application’s confidentiality, integrity, and availability. Successful exploitation therefore permits a complete takeover of the product. The weakness carries a CVSS v3.1 base score of 7.5, reflecting moderate to severe risk, though the description notes difficulty in exploitation.
Affected Systems
Oracle Advanced Benefits versions 12.2.7 through 12.2.15 are affected. The product is part of the Oracle E‑Business Suite and is deployed by organizations that use the Affordable Care Act module.
Risk and Exploitability
The CVSS base score of 7.5 coupled with an EPSS score of less than 1 % indicates that while the potential impact is high, the likelihood of active exploitation is low. The vulnerability can be leveraged by an attacker who has network access to the web interface and holds a low‑privilege account; no user interaction is required. Once the condition is met, exploitation results in a complete takeover of the application. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment