Impact
The vulnerability lies in the Search Integration Engine component of Oracle E‑Business Suite Secure Enterprise Search. An attacker who only has low‑privileged network access over HTTP can exploit the flaw to create, delete, or modify critical data. The impact is severe loss of confidentiality and integrity because the attacker gains the ability to alter or access all data exposed by the Secure Enterprise Search feature.
Affected Systems
Oracle Corporation’s Oracle E‑Business Suite Secure Enterprise Search product, versions 12.2.3 through 12.2.15, contains the affected Search Integration Engine. Only these supported releases include the vulnerable component.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high‑severity flaw that is remotely exploitable over HTTP with low attack complexity and requires a low‑privileged attacker. The EPSS score of less than 1% reflects a low overall probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nevertheless, its high confidentiality and integrity impact makes it a priority for affected systems.
OpenCVE Enrichment