Impact
The vulnerability is an access control flaw that allows a low‑privileged attacker with network access via HTTP to bypass internal controls in Oracle Process Manufacturing Financials. This flaw can enable the attacker to create, delete, or modify critical data and read any data stored by the application. The weakness is classified as CWE‑284, leading to high confidentiality and integrity impacts while availability is not affected.
Affected Systems
Oracle Process Manufacturing Financials, part of Oracle E‑Business Suite, affects versions 12.2.3 through 12.2.15. Other versions are not known to be impacted by this issue.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high‑severity vulnerability that can be exploited over the network without user interaction. The EPSS score of less than 1% suggests that exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw is easily exploitable by an attacker with low privileges and network access to the Internal Operations component, and it can result in unauthorized data creation, deletion, modification, and read access to all data stored in the system.
OpenCVE Enrichment