Impact
Oracle Flow Manufacturing in Oracle E-Business Suite contains a weakness that allows an attacker with only low privileges and network access over HTTP to execute privileged operations inside the application’s internal operations component. The flaw results in a full takeover of the application, giving the attacker complete control over the system, its data, and any services it hosts. The vulnerability is an improper access control error that exposes sensitive functionality to unauthorized users.
Affected Systems
The affected product is Oracle Flow Manufacturing as part of Oracle E‑Business Suite. All installations from version 12.2.3 through 12.2.15 are impacted. The flaw exists in the internal operations component and applies regardless of deployment topology or environment configuration.
Risk and Exploitability
The CVSS base score is 8.8, indicating high severity with complete confidentiality, integrity, and availability impacts. The EPSS score is below 1%, suggesting a low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploitation is known. The likely attack vector is a direct HTTP connection from a remote host, requiring only low‑privilege access to the application. An attacker can exploit the flaw without elevated privileges or special preconditions beyond network reachability and the ability to interact with the HTTP interface.
OpenCVE Enrichment