Impact
Oracle Advanced Benefits version 12.2.15 contains an easily exploitable flaw that allows an attacker with high‑privileged credentials and network access via HTTP to compromise the application. The vulnerability permits unauthorized read, update, insert, or delete access to data accessed through Oracle Advanced Benefits. The weakness is a flaw in access control and authorization, classified as CWE‑284 and CWE‑863. The result is the potential disclosure of critical data and the ability to modify or delete records that could undermine the integrity of the system.
Affected Systems
Affected systems consist of the Oracle Advanced Benefits component of Oracle E‑Business Suite, specifically version 12.2.15. The CNA records identify only this product and version as impacted; no other vendors or product variants are listed.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 indicates a moderate‑to‑high severity vulnerability, with significant confidentiality and integrity impacts. The EPSS score of less than 1% points to a relatively low probability of exploitation in the wild, and the issue is not in the CISA KEV catalog. Attackers would need network connectivity to the application via HTTP and high‑privileged accounts within Oracle Advanced Benefits to leverage the flaw. Because the scope is marked as Changed, successful exploitation could extend beyond the application to affect other related Oracle products.
OpenCVE Enrichment