Impact
A vulnerability exists in the Item Catalog component of Oracle Product Hub within Oracle E‑Business Suite that enables a low‑privileged attacker with network access through HTTP to delete, insert, or update accessible data, read a subset of the data, or perform a partial denial of service. This improper access control flaw (CWE‑284) allows unauthorized manipulation of data and exposure of sensitive information, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Oracle Corporation’s Oracle Product Hub for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Users of the Item Catalog feature within this product range are exposed to the described risks.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, amplified by the low attack complexity and low privileges required; no user interaction is needed. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for data alteration and service disruption warrants immediate attention.
OpenCVE Enrichment