Impact
The vulnerability arises from improper authorization controls in the RDBMS and UI components of Oracle Call Center Technology. It enables a low‑privileged attacker with network connectivity over HTTP to perform unauthorized updates, inserts, or deletions of accessible data and to read a subset of data that should be protected. The flaw results in confidentiality and integrity impacts on the application data.
Affected Systems
Oracle Call Center Technology, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. Only these releases are mentioned; earlier or later versions are not specified as vulnerable.
Risk and Exploitability
This risk has a CVSS 3.1 base score of 5.4, indicating moderate severity. EPSS is reported to be below 1%, suggesting a low likelihood of widespread exploitation, though the vulnerability is described as easily exploitable. The flaw is not listed in CISA’s KEV catalog and can be triggered by an attacker who has network access to the HTTP interfaces of the Call Center application. Being a low‑privileged access control issue, exploitation requires no special credentials, only HTTP connectivity to the affected server.
OpenCVE Enrichment