Impact
This vulnerability in Oracle Advanced Benefits is an improper access control flaw (CWE‑284) that allows an attacker with low privileges to access the system through a network HTTP endpoint and create, delete, or modify critical data. The impact is a loss of data integrity, as an attacker can alter or remove information that the business considers reliable. The issue is not about privilege escalation; the attacker simply needs low‑privileged credentials that would normally restrict them from performing these actions.
Affected Systems
Oracle Corporation’s Advanced Benefits version 12.2.15 is affected, specifically within the Internal Operations component. The CVE notes that the flaw’s scope can impact additional Oracle E‑Business Suite products, potentially allowing unauthorized data manipulation beyond the Benefits application.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 indicates a high integrity impact. The EPSS score is below 1%, suggesting that exploitation is currently low probability, yet the HTTP entry point can be reached over the network, so the flaw remains remotely exploitable. The CVE is not listed in the CISA KEV catalog, but the potential for widespread data alteration across the suite elevates its importance for organizations running the affected version.
OpenCVE Enrichment