Impact
Oracle Lease and Finance Management, part of Oracle E‑Business Suite, has a vulnerability in the Internal Operations component that permits a high‑privileged attacker who can reach the system over HTTP to exploit the flaw, resulting in total takeover of the application and loss of confidentiality, integrity, and availability for affected data and processes.
Affected Systems
Oracle Lease and Finance Management versions 12.2.14 through 12.2.15 are affected. These instances provide finance functionality within Oracle E‑Business Suite.
Risk and Exploitability
The CVSS v3.1 score of 7.2 indicates a high impact with low complexity. The EPSS score of less than 1% suggests that exploitation attempts are rare or currently unobserved, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP and requires a high‑privileged attacker with access rights. Successful exploitation would result in complete takeover of the application, causing unacceptable damage to the organization’s financial data and processes.
OpenCVE Enrichment