Impact
A flaw in the Lease Authoring component of Oracle Lease and Finance Management allows an attacker with low privileges and HTTP network access to bypass authorization checks and perform unauthorized updates, inserts, deletions, and read operations on protected data, as well as trigger a partial denial of service. The weakness is rooted in improper access control and missing authorization checks, corresponding to CWE-269, CWE-284, and CWE-306. The impact spans confidentiality, integrity, and availability of the application data, though each tier of impact is classified as low.
Affected Systems
Oracle Lease and Finance Management, part of Oracle E‑Business Suite, is affected for releases 12.2.3 through 12.2.15. The Lease Authoring component must be evaluated for exposure to external HTTP traffic, as the vulnerability can be exploited by any user that can connect to the application over the network.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, and the EPSS score falling below 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because only low privileges and direct HTTP access are required, organizations that expose Lease and Finance Management to the network face a significant risk of unauthorized data manipulation and partial service disruption and should remediate promptly.
OpenCVE Enrichment