Impact
The vulnerability in the Oracle Supply Chain Globalization component "Copy Inventory Organization" stems from inadequate input validation and weak authorization controls, allowing an attacker with only low‑privileged HTTP access to send crafted requests that can perform unauthorized updates, inserts, or deletions on protected data, read sensitive information that should be restricted, and trigger a partial denial of service. These capabilities, reflected in the identified CWEs, lead to modifications and disclosure of operational data and interruption of business processes.
Affected Systems
Affected software is Oracle Supply Chain Globalization, part of Oracle E‑Business Suite. Identified vulnerable versions include 12.2.3 through 12.2.15. Oracle Corporation is the responsible vendor and the Oracle Supply Chain Globalization product hosts the Copy Inventory Organization functionality that is impacted.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 signals moderate severity, with low impacts on confidentiality, integrity, and availability. The EPSS score is below 1 %, indicating a very low chance of exploitation in production networks, and the vulnerability is not listed in the CISA KEV catalog. Still, because the weakness can be reached via a public HTTP endpoint and requires only low‑privileged credentials, it constitutes a non‑negligible threat; a successful attack could alter critical inventory data, disclose enterprise information, and partially disrupt operations.
OpenCVE Enrichment