Impact
A flaw in the Oracle Process Manufacturing Logistics internal operations component allows an attacker who can reach the application over HTTP to bypass normal access controls and obtain confidential information. If successfully exploited, the attacker can read sensitive data or perform update, insert, or delete operations on that data, compromising both confidentiality and integrity. The weakness is an improper access control flaw (CWE‑284).
Affected Systems
Oracle Corporation’s Oracle Process Manufacturing Logistics component of Oracle E‑Business Suite is vulnerable in all supported releases from 12.2.3 through 12.2.15. The vulnerability affects the internal operations module that is exposed over HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 reflects the severity of the confidentiality impact and limited integrity impact. The EPSS score of less than 1 % suggests that while exploitation is possible, it is unlikely to be automated or widespread at present. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. The likely attack vector is a remote web request—an attacker with network access can send HTTP requests to the affected component without needing elevated privileges.
OpenCVE Enrichment