Impact
A low‑privileged adversary with network connectivity via HTTP can exploit a flaw in Oracle Bills of Material, enabling unauthorized creation, deletion or alteration of critical data. This access control weakness can also grant unchecked read access to all data handled by the component, potentially exposing sensitive information. The vulnerability is identified as CWE‑284.
Affected Systems
Oracle Bills of Material, part of Oracle E‑Business Suite, is affected for all releases version 12.2.13 through 12.2.15. These versions remain supported and are the only ones explicitly targeted by the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates significant confidentiality and integrity impact. The attack vector is via network (HTTP) and requires only low privileges, but not user interaction. With an EPSS score of less than 1 % and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation remains modest, yet the potential damage is high should an attacker succeed.
OpenCVE Enrichment