Impact
The flaw is an Authorization Bypass in Oracle Advanced Benefits 12.2.15, classified as CWE‑284. The vulnerability permits a low‑privileged attacker with network access via HTTP to compromise the application, resulting in unauthorized access to critical data or complete possession of all data reachable by the application. This leads to a high confidentiality impact while integrity and availability remain unaffected.
Affected Systems
Oracle Advanced Benefits version 12.2.15, part of Oracle E‑Business Suite. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate risk. The EPSS score is below 1 %, suggesting a very low expected exploitation probability. The vulnerability is not listed in the CISA KEV catalog. A low‑privileged attacker can exploit the weakness over a network-based HTTP connection without needing elevated privileges or special authorization beyond the baseline access level.
OpenCVE Enrichment