Impact
A flaw in Oracle Sales for Handhelds permits a low‑privileged user with network access to modify or delete data, read restricted information, and trigger a partial service outage. The vulnerability is grounded in improper enforcement of access controls (CWE‑284), leading to confidentiality, integrity, and availability impacts. Successful exploitation results in unauthorized database changes, exposure of internal data, and disruption of business operations.
Affected Systems
Oracle Corporation’s Oracle Sales for Handhelds, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite. These affected releases are listed under the component Outlook Sync Win 32 and are part of the broader Sales for Handhelds product line.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, yet the low exploitation difficulty and low privilege requirement raise its practical threat. The EPSS score of less than 1% signals currently low probability of exploitation in the wild, and the vulnerability is not yet catalogued in CISA’s KEV list. Nonetheless, network‑based attackers can exploit the bug through HTTP traffic to gain unauthorized access and disrupt service.
OpenCVE Enrichment