Impact
The vulnerability resides in the Quality Management Specs component of the Oracle Process Manufacturing Product Development, where a low‑privileged attacker with network access over HTTP can exploit the flaw. This flaw allows the attacker to compromise the application, leading to a full takeover. The impact covers confidentiality, integrity and availability, as the CVSS vector shows high impacts on all three. The weakness is identified as CWE‑284, which indicates an issue with insufficient authorization.
Affected Systems
Oracle Process Manufacturing Product Development (Oracle E‑Business Suite) version 12.2.15 is affected. The product is specifically the Quality Management Specs component. No other versions are listed as vulnerable.
Risk and Exploitability
CVSS score 8.8 indicates high severity, but the EPSS score is < 1%, suggesting very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would require only network access to the HTTP port and a low‑privileged account or guest access; no additional credentials are needed, making the attack relatively easy if the environment is exposed. Because the flaw is not yet widely exploited publicly, the risk is high but the likelihood remains low.
OpenCVE Enrichment