Impact
An unknown software defect in Oracle Complex Maintenance, Repair and Overhaul enables a low privileged network attacker to read all data exposed by the application and to cause a partial denial of service. The problem afflicts only the Production component of the product, but because the vulnerability changes the security scope, successful exploitation can affect other Oracle E‑Business Suite modules. The flaw does not require user interaction, can be triggered over HTTP, and requires only high authentication complexity and a low privilege level to execute.
Affected Systems
The affected product is Oracle Complex Maintenance, Repair and Overhaul, a component of Oracle E‑Business Suite, with supported versions ranging from 12.2.3 to 12.2.15. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates moderate to high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but because the attack vector is network‑based with no user interaction and involves a scope change the likelihood of exploitation for attackers who can reach the target via HTTP is significant. The vulnerability allows unauthorized information disclosure and a partial availability impact, giving an attacker the ability to exfiltrate confidential data or disrupt services.
OpenCVE Enrichment