Impact
Vulnerability in the Attachments component of Oracle Document Management and Collaboration allows an unauthenticated attacker that can reach the service over HTTP to perform unauthorized updates, inserts, deletes, reads, and to cause a partial denial of service. The flaw is a case of Improper Access Control (CWE‑284) that directly compromises confidentiality, integrity, and availability of the data managed by the application.
Affected Systems
Oracle Document Management and Collaboration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected, as listed by Oracle for this incident.
Risk and Exploitability
The CVSS score of 7.3 classifies this vulnerability as high severity. The EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need no authentication and only HTTP network connectivity to target the service, making the attack vector simple but limited to HTTP access. With these privileges the attacker can modify or delete data, read sensitive information, and disrupt service availability, all within the scope of the Document Management and Collaboration domain.
OpenCVE Enrichment