Impact
The vulnerability lies in the Create Item Instance component of Oracle E‑Business Suite’s Oracle Installed Base. A low‑privileged attacker with network access over HTTP can create, delete, or modify records in the installed base system without proper authorization, allowing unauthorized access to critical data and compromising the integrity of the entire base.
Affected Systems
Oracle Installed Base product of Oracle E‑Business Suite, versions 12.2.4 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.1 indicates high severity with significant confidentiality and integrity impact. The attack vector is network‑based over HTTP (AV:N), requiring low effort (AC:L) and low privileges (PR:L) while no user interaction is needed (UI:N). The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, yet systems with open HTTP access to the Installed Base are potentially vulnerable.
OpenCVE Enrichment