Impact
A vulnerability in Oracle Shipping Execution within Oracle E‑Business Suite allows a high‑privileged attacker who has network access through HTTP to compromise the system. The flaw can be leveraged by skilled attackers to take full control of the Shipping Execution component, compromising confidentiality, integrity, and availability. The weakness is rated with a CVSS 3.1 base score of 6.6, indicating significant impact if successfully exploited.
Affected Systems
Oracle Shipping Execution versions 12.2.3 through 12.2.15 are affected. These releases belong to Oracle E‑Business Suite’s Internal Operations component and are delivered by Oracle Corporation. The affected product is identified by the CPE string cpe:2.3:a:oracle:shipping_execution:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS vector reveals that the attack requires network access, high attack complexity, and high privileges, with no user interaction needed. Although the exploitation is challenging, the impact is severe enough to warrant urgent attention. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that widespread exploitation has not yet been documented, but the potential remains high for organizations still running the affected versions.
OpenCVE Enrichment