Impact
A vulnerability exists in the Oracle Product Hub component "Internal Operations" that permits a low‑privileged attacker with network access via HTTP to compromise the product. It is classified as CWE‑284 (Improper Access Control). Exploitation may lead to full takeover of the product, destroying confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Oracle Product Hub versions 12.2.3 through 12.2.15, which are part of Oracle E‑Business Suite. The affected vendor is Oracle Corporation.
Risk and Exploitability
The CVSS base score is 8.5, indicating high severity, while the EPSS score is < 1 %, suggesting that the likelihood of exploitation is currently low but it is not guaranteed to be safe. The vulnerability is not listed in KEV, but the scope change (S:C) means that compromised Oracle Product Hub could affect other Oracle products. The attack vector is via network using HTTP, and the attacker only needs low privilege credentials to launch the exploit.
OpenCVE Enrichment