Impact
This vulnerability occurs in the Oracle Price Protection component of Oracle E‑Business Suite when accessed via HTTP. The flaw allows an attacker with low privileges and network access to create, delete, or alter data records. It also permits the reader to view subsets of the data, thereby impacting confidentiality and integrity. The CVSS vector indicates a network-based attack (AV:N) that requires low authorization (PR:L) and has no requirement for user interaction (UI:N).
Affected Systems
Oracle Corporation’s Oracle Price Protection product is affected, specifically versions 12.2.3 through 12.2.15. These installations rely on secure price data management.
Risk and Exploitability
The CVSS base score of 7.1 classifies the vulnerability as high severity, though the EPSS score of less than 1% suggests exploitation is unlikely at the current moment. The vulnerability is not listed in the CISA KEV catalog and thus has no known active exploits. However, because the attack surface is a publicly exposed HTTP interface, a determined adversary could leverage this flaw to compromise data integrity and confidentiality, especially if other access controls are weak.
OpenCVE Enrichment