Impact
The Oracle Product Hub component of Oracle E‑Business Suite contains an improper access control flaw (CWE‑284). A low‑privileged attacker who can reach the product via HTTP can create, delete, or modify any data stored in Oracle Product Hub. The vulnerability allows the attacker to bypass existing authentication checks, resulting in confidentiality and integrity compromise of all data accessible through the hub.
Affected Systems
Affected are Oracle Corporation products under the Oracle Product Hub umbrella within Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are impacted. No other products or later versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity problem. The EPSS score is below 1 %, suggesting that widespread exploitation is unlikely at present, and the vulnerability is not yet listed in CISA’s KEV catalog. However, because the attack vector is network‑based and requires only local or remote HTTP access, a low‑privileged attacker could exploit it quickly if no network restrictions are in place.
OpenCVE Enrichment