Impact
A weakness in Oracle Price Protection, identified as an access control failure (CWE-284), allows an attacker with low privileges who can reach the system over HTTP to create, delete, or modify critical data. The vulnerability also grants read access to all data managed integrity of information handled, with a CVSS 3.1 base score of 8.1.
Affected Systems
Oracle Corporation's Oracle Price Protection component of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15, are affected. No other vendors or products are identified as vulnerable.
Risk and Exploitability
The CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N shows a high severity remote vulnerability that requires low privilege and no user interaction. The EPSS score is under 1%, and the issue is not listed in the CISA KEV catalog, indicating that widespread exploitation has not been observed. The likely attack path proceeds over HTTP from a network-accessible host, exploiting the missing or insufficient access controls within the product.
OpenCVE Enrichment