Impact
Oracle Learning Management is vulnerable to an unauthenticated HTTP attack that can be carried out by any network user without credentials. The flaw permits the attacker to update, insert, or delete data that a legitimate user should not be able to change and to read a subset of data that should remain confidential. The CVSS 3.1 Base Score of 6.5 indicates moderate overall severity with notable impacts on confidentiality and integrity.
Affected Systems
The affected product is Oracle Learning Management, part of Oracle E-Business Suite. Versions 12.2.3 through 12.2.15 are susceptible. The vulnerability is categorized under the Internal Operations component.
Risk and Exploitability
Although no EPSS score is available and the vulnerability is not listed in CISA's KEV catalog, the lack of authentication combined with an open HTTP interface suggests that it can be exploited remotely by an unauthenticated attacker with network connectivity. The moderate CVSS score reflects the fact that while the vulnerability can expose and alter data, it does not lead to full system compromise or denial of service. Attackers would need only basic network access and no special configuration to take advantage of the flaw.
OpenCVE Enrichment