Impact
The Oracle iSupport product is affected by a vulnerability in the Call Back component, which allows a low‑privileged attacker to obtain unauthorized read, insert, update, or delete access to some internal data. The weakness stems from improper authorization checks, leading to permission escalation and potential loss of confidentiality and integrity for the affected data.
Affected Systems
Affects Oracle E‑Business Suite versions 12.2.3 through 12.2.15 of Oracle iSupport. The vulnerability is present in the Call Back component. All installations of these versions exposed over HTTP are susceptible.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 signals a moderate severity. The EPSS score is below 1%, indicating a low probability of widespread exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Attacks can be carried out over the network via HTTP by users with limited privileges, without user interaction. The impact is limited to confidentiality and integrity of selected data, with no denial‑of‑service effect.
OpenCVE Enrichment