Impact
This vulnerability in Oracle Enterprise Asset Management permits a low‑privileged attacker who can reach the system over HTTP to compromise it, but requires another user to provide interaction for the final exploitation step. The flaw is an access control issue, classified as CWE‑284. If exploited, the attacker can gain unauthorized access to critical data, as well as read, update, insert, or delete data within the system, potentially achieving full access to all data the product exposes.
Affected Systems
Oracle Corporation's Oracle Enterprise Asset Management, a component of Oracle E‑Business Suite, is impacted. Susceptible versions range from 12.2.3 through 12.2.15, inclusive. The product is identified in the Oracle Security Alert August 2026.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, with confidentiality and integrity impacts but no availability impact. The EPSS score is less than 1 %. This CVE is not listed in CISA’s KEV catalog. Exploitation requires a low‑privileged attacker with network access via HTTP and user interaction from a different person. The likely attack vector is HTTP, and the scope change may affect additional Oracle products. Consequently, the risk is substantial for environments where the component is exposed to LAN or WAN traffic.
OpenCVE Enrichment