Impact
The vulnerability in Oracle Proposals, part of Oracle E‑Business Suite, allows a low‑privileged user with network access over HTTP to modify, insert, or delete records, read restricted data, and trigger a partial denial of service. These actions impact the confidentiality, integrity, and availability of the proposal data as reflected by a CVSS 3.1 Base Score of 6.3 and its classification as CWE‑200.
Affected Systems
Oracle Proposals component of Oracle E‑Business Suite, affected versions 12.2.3 through 12.2.15.
Risk and Exploitability
Exploitation requires only network connectivity to the Oracle Proposals HTTP interface and does not need privileged authentication. The low attack complexity and low privilege requirement yield a moderate severity path, while the EPSS score of less than 1% indicates a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment