Impact
The vulnerability in Oracle Price Protection permits a low‑privileged network attacker to perform unauthorized insert, update, or delete operations on protected data and to read restricted data. Additionally, the attacker can trigger a partial denial of service. These capabilities expose weaknesses in access control and information confidentiality, aligned with CWE‑200, CWE‑269, and CWE‑284, and result in confidentiality, integrity, and availability impacts as reflected in the CVSS vector.
Affected Systems
Oracle Corporation’s Oracle Price Protection component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. These releases fall under the Oracle E‑Business Suite product family.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 Base Score of 6.3, indicating moderate severity. The EPSS score of less than 1% implies a low but nonzero exploitation likelihood. It is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request that a user with low privileges can send to an exposed endpoint in the Price Protection service, leveraging insufficient access controls to gain unauthorized data modification, read, or partial service disruption.
OpenCVE Enrichment