Impact
The vulnerability resides in the Internal Operations component of Oracle Lease and Finance Management, an Oracle E‑Business Suite application. A low‑privileged attacker who can reach the application over HTTP can leverage a difficult‑to‑exploit flaw that grants them unauthorized privilege escalation, allowing complete takeover of the application. This results in full compromise of confidentiality, integrity, and availability, and corresponds to CWE‑284, an authorization weakness.
Affected Systems
Oracle Lease and Finance Management, part of Oracle E‑Business Suite, is affected. The advisory lists the vulnerable releases as versions 12.2.11 through 12.2.15. No other vendors or product lines are mentioned in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 highlights high severity, while the EPSS score of less than 1 % indicates that current exploit prevalence is very low. It is not included in the CISA KEV catalog. The authoritative vector implies that an attacker only needs network connectivity to the application’s HTTP interface and a low level of privilege; no local access is required.
OpenCVE Enrichment