Impact
The issue is a low-privilege vulnerability in Oracle Public Sector Financials that can be triggered via an HTTP request. An attacker with minimal privileges and network access may influence the system to perform unauthorized updates, inserts, or deletes, and read restricted data. The weakness results from improper access control (CWE-284) and leads to confidentiality and integrity impacts.
Affected Systems
Oracle Public Sector Financials, part of Oracle E-Business Suite, Internal Operations component. Affected versions are 12.2.3 through 12.2.15. The vulnerability may also influence other products due to a scope change.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires a low-privileged attacker, from a user other than the attacker. The attack path likely involves the attacker sending a crafted HTTP request to the vulnerable endpoint while exploiting the improper access control to elevate privileges.
OpenCVE Enrichment