Impact
The vulnerability resides in Oracle MES for Process Manufacturing, a component of Oracle E‑Business Suite’s Internal Operations. It permits an unauthenticated attacker who can reach the system over HTTP to read and modify critical business data. Successful exploitation requires human interaction from an individual other than the attacker, and the flaw can affect additional Oracle products through a scope change. The result is potential disclosure of confidential data and unauthorized updates, inserts, or deletions that compromise data integrity.
Affected Systems
Oracle Corporation’s Oracle MES for Process Manufacturing, versions 12.2.3 through 12.2.15, is affected. This product is part of the Oracle E‑Business Suite’s Internal Operations component. The flaw can be triggered over HTTP and is limited to the stated versions, though the vulnerability’s scope may extend to other Oracle products sharing similar components.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 signals a high severity, especially for confidentiality, and indicates that the vulnerability is easily exploitable with low attack complexity and no need for user credentials. Although the EPSS score is not available, the known exploitability remains high due to the attacker’s ability to reach the system over HTTP and the requirement for a human interaction from a third party to trigger the exploit. Because the vulnerability may affect additional products, the potential impact is amplified by scope change. The attack vector is likely an unauthenticated network traffic over HTTP, possibly activated through a social engineering‑style interaction.
OpenCVE Enrichment