Impact
A low privileged attacker with network access via HTTP can exploit a vulnerability in Oracle Marketing to perform unauthorized update, insert, or delete operations on data, read restricted data, and trigger a partial denial of service. The flaw enables manipulation of Oracle Marketing accessible data and can interrupt services, affecting confidentiality, integrity, and availability in a limited scope.
Affected Systems
Oracle Marketing, part of Oracle E-Business Suite (Audience component), versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates a moderate risk, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable system over standard HTTP traffic, potentially using the absence of proper access controls identified by CWE-284 to elevate their privileges and manipulate data or disrupt services.
OpenCVE Enrichment