Impact
A low‑privileged attacker with network access can exploit a flaw in the Oracle Public Sector Financials Internal Operations component to gain full control of the application. The vulnerability is remotely exploitable over HTTP and can compromise confidentiality, integrity and availability in a single successful attack, as reflected by a CVSS 3.1 Base Score of 8.8.
Affected Systems
Oracle Public Sector Financials, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV and no publicly disclosed exploit code is known, but the attack vector is likely over the public internet via an unauthenticated HTTP request to the vulnerable component. Successful exploitation could result in a full takeover of the application, exposing all data and functions.
OpenCVE Enrichment