Impact
The vulnerability is located in the Claim LOV component of Oracle Trade Management, part of Oracle E‑Business Suite. It stems from insufficient authorization and authentication controls, allowing an attacker with only low‑privilege network access over HTTP to exploit the flaw. Successful exploitation can lead to loss of confidentiality, integrity and availability, effectively enabling the attacker to take full control of the Oracle Trade Management instance.
Affected Systems
Oracle Corporation’s Oracle Trade Management, versions 12.2.3 through 12.2.15, are affected. These releases are part of the Oracle E‑Business Suite and are vulnerable to the Claim LOV flaw.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high‑severity vulnerability with full impact on confidentiality, integrity and availability. The EPSS score is below 1%, suggesting the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw is easily exploitable over HTTP by an attacker who only needs low‑privilege credentials, making it a serious risk for exposed systems. The attack vector is network‑based, with no user interaction required.
OpenCVE Enrichment