Impact
The vulnerability exists in the internal operations component of Oracle Product Hub and allows an attacker with low privileges and network access over HTTP to bypass authentication and take complete control of the application. The result is loss of confidentiality, integrity, and availability because the attacker can access, modify, or delete data and disrupt services. This weakness is manifested through improper privilege management (CWE-269), authentication bypass (CWE-287), and missing authentication checks (CWE-306).
Affected Systems
Affected systems are Oracle Product Hub, a component of Oracle E‑Business Suite, for versions 12.2.3 through 12.2.15. No other product releases are listed as affected in the current advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Likely attack conditions involve a low‑privileged attacker able to reach the Product Hub over HTTP, possibly using an unsecured or mis‑configured endpoint that does not enforce proper authentication. Consequently, the risk profile remains high, but the chance of real‑world exploitation is low as of the time of analysis.
OpenCVE Enrichment