Impact
This access‑control weakness in Oracle Item Master, affecting versions 12.2.3 through 12.2.15, enables a low‑privileged attacker who can reach the application via HTTP to create, modify, or delete items, and to read a subset of the data. The vulnerability is a CWE‑284 flaw that subverts normal permissions and compromises both confidentiality and integrity of the company’s item master records.
Affected Systems
Oracle Corporation’s Item Master product is the only vendor/product impacted by this CVE. Systems running any of the Oracle Item Master releases from 12.2.3 to 12.2.15 are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate severity, reflecting low confidentiality and integrity impact but requiring no authentication. The EPSS score of less than 1% suggests that exploitation is currently considered rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the lack of an authentication barrier, coupled with the ability to inject, modify, or delete records, means that a low‑privileged attacker with network access can permanently alter critical business data. Monitoring and prompt remediation are recommended.
OpenCVE Enrichment