Impact
A network‑directed vulnerability in Oracle U.S. Federal Financials enables an attacker with low privileges on the local network to execute arbitrary code and gain complete control of the application. The weakness allows the attacker to bypass authentication checks and assume full administrative rights, thereby compromising confidentiality, integrity, and availability of all data processed by the system. The CVSS 3.1 score of 8.8 and vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H confirm the severity and ease of exploitation. This is a weak access control vulnerability, classified as CWE‑284.
Affected Systems
The vulnerability affects Oracle U.S. Federal Financials, part of Oracle E‑Business Suite’s Internal Operations component, for all supported releases from 12.2.3 through 12.2.15.
Risk and Exploitability
Exploitation requires only network access over HTTP from a low‑privileged position; no user interaction is needed. The lack of a publicly disclosed EPSS score and absence from the CISA KEV catalog mean that exploitation likelihood is uncertain, but the high CVSS score and straightforward attack path provide a strong incentive for adversaries. Organizations should assume the risk of compromise until a patch is applied.
OpenCVE Enrichment