Impact
The flaw in Oracle Installed Base allows a low‑privileged user who can reach the product over HTTP to create, delete, or modify critical data and obtain full read access to all data exposed by the system. The result is a loss of confidentiality, breach of integrity, and a partial denial of service. The weakness stems from inadequate authentication checks and exposure of sensitive information (CWE‑200, CWE‑269, CWE‑284). The description states that the attacker must be low‑privileged, and it is inferred that unauthenticated access is not required, as the statement does not mention it explicitly.
Affected Systems
Oracle Corporation’s E‑Business Suite, specifically the Create Item Instance component of Oracle Installed Base, is affected on versions 12.2.3 through 12.2.15. Any installation of these versions that exposes the HTTP interface to low‑privileged accounts is vulnerable.
Risk and Exploitability
The CVSS‑3.1 base score of 8.3 highlights high confidentiality and integrity impact with moderate availability impact. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack requires only network access and a low‑privileged account, making environments that expose the HTTP endpoint a significant risk. No additional user interaction or pre‑existing software condition is required for exploitation.
OpenCVE Enrichment