Impact
The vulnerability resides in the Role Based Security component of Oracle Product Hub. An attacker who is a low‑privileged user and can reach the Product Hub over HTTP can exploit this flaw to update, insert or delete data, read data not normally accessible, and force the service into a partial denial of service. The weakness is an improper access control (CWE‑284) that permits operations beyond the intended permissions. Successful exploitation compromises confidentiality, integrity and availability of the Product Hub data and functions.
Affected Systems
Oracle Product Hub, versions 12.2.3 through 12.2.15. The flaw is present on all supported releases within this range and can affect any installations that expose the Product Hub services to untrusted networks.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. Because the attack requires only network access over HTTP and low privileges, the EPSS score is very low, under 1 %, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Even with a low exploitation probability, the potential impact on business data and operations warrants timely remediation. The likely attack path involves an attacker sending crafted HTTP requests that gain elevated permissions within the Product Hub service, leading to unauthorized data changes or a partial service outage.
OpenCVE Enrichment