Impact
The Calendar Synchronizations component of Oracle Common Applications Calendar allows a low‑privileged attacker with network access via HTTP to perform unauthorized insert, update or delete operations on calendar data, read restricted records, and trigger a partial denial of service. This is reflected in the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) and maps to CWE‑200, CWE‑284 and CWE‑89 weaknesses. The vulnerability permits tampering with data integrity, disclosure of confidential calendar information and disruption of service for authorized users.
Affected Systems
Oracle Common Applications Calendar, versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 indicates moderate severity. Exploitation requires only network connectivity to the vulnerable HTTP endpoint and does not need user interaction, but the EPSS score of less than 1 % shows a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would target the Calendar Synchronizations endpoint to gain unauthorized data modification or partial service disruption as described by the vendor advisory.
OpenCVE Enrichment