Impact
Vulnerability in the Cost Planning component of Oracle 12.2.3 through 12.2.15 allows a high privileged attacker with network access through HTTP to fully compromise the application. The impact is significant, with confidentiality, integrity, and availability all affected, and the flaw is a CWE‑284 access control weakness that permits privilege escalation and takeover.
Affected Systems
Oracle Cost Management from Oracle Corporation, specifically the Cost Planning component; affected releases include 12.2.3 to 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates moderate severity, meaning a successful exploit would provide full confidentiality, integrity, and availability impacts. However, the vulnerability requires a high‑privileged attacker with direct HTTP network access and the EPSS score is below 1%, demonstrating a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, which further underscores the lower risk rating. Attackers who meet the prerequisite conditions could coerce the application into executing administrative actions, effectively gaining control of the Cost Management system.
OpenCVE Enrichment