Impact
A flaw in Oracle Shipping Execution, part of Oracle E-Business Suite, lets an attacker with high privileges and network access through HTTP try to take control of the component. The vulnerability can expose, alter, or delete data and disrupt the service, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Shipping Execution versions 12.2.3 through 12.2.15 are affected. These releases belong to the Internal Operations component of Oracle E-Business Suite and are delivered by Oracle Corporation. The vulnerability exists in the internal operations processing of the Shipping Execution module.
Risk and Exploitability
The CVSS v3.1 base score of 6.6 indicates notable impact, with the attack vector requiring network access, a high attack complexity, high privileges, and no user interaction. Exploitation is considered difficult, yet the availability of the flaw and its high-privilege impact mean organizations running the affected releases should consider it serious. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation to date, but the potential remains if the conditions are met.
OpenCVE Enrichment