Impact
The Oracle Advanced Benefits component of Oracle E‑Business Suite suffers an authorization flaw that permits attackers with low‑privilege credentials and network access over HTTP to modify, insert, or delete data, read restricted information, and cause a partial denial of service. This flaw stems from an improper check of user permissions (CWE‑284) and impacts the confidentiality, integrity, and availability of the application.
Affected Systems
The vulnerable product is Oracle Advanced Benefits in Oracle E‑Business Suite. Versions from 12.2.4 up through 12.2.15 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 signifies a moderate security risk. EPSS is below 1 % suggesting exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs low‑privilege membership and network connectivity over HTTP to exploit the flaw, which can lead to unauthorized data manipulation or partial denial of service.
OpenCVE Enrichment