Impact
A flaw in Oracle Order Management’s Product Diagnostic Tools allows a low‑privileged attacker who can reach the system over HTTP to create, delete or modify critical data or gain full read access. This is an Access Control flaw (CWE‑284) with a CVSS 3.1 Base Score of 8.1, indicating high confidentiality and integrity impact and a relatively straightforward exploitation path.
Affected Systems
Oracle Order Management, part of Oracle E‑Business Suite, is affected for versions 12.2.4 through 12.2.15. The vulnerability applies to installations that expose the Product Diagnostic Tools HTTP interface and are reachable from the network. No other versions or components are believed to be impacted.
Risk and Exploitability
The high CVSS score reflects significant risk, yet the EPSS score of less than 1% suggests that active exploitation by threat actors is currently low. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely target the HTTP interface of the affected product; they need only low privileges in the system, making the risk real for organizations with inadequate network segmentation or role‑based access controls.
OpenCVE Enrichment