Impact
The vulnerability, found in the Internal Operations component of Oracle Process Manufacturing Systems, is an easily exploitable improper access control flaw (CWE‑284). A low‑privileged attacker with network access via HTTP can compromise the system, achieving unauthorized creation, deletion or modification of critical data and gaining full read access to all data available in the system.
Affected Systems
Oracle Process Manufacturing Systems, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 contain the flaw, while newer releases are not listed as vulnerable.
Risk and Exploitability
With a CVSS v3.1 base score of 8.1, the vulnerability carries high severity, inflicting major confidentiality and integrity damage while availability is not affected. The EPSS score is less than 1 %, indicating a low but non‑zero likelihood of exploitation in the wild, and the flaw is not currently listed in the CISA known‑exploited vulnerabilities catalog. Attackers likely pivot through the HTTP interface exposed by the Internal Operations component and require only low privilege credentials, making the vulnerability readily actionable for threats that already have network reach into the affected environment.
OpenCVE Enrichment