Impact
The flaw is an improper access control in the Internal Operations component of Oracle Public Sector Financials. A user with only low privileges can exploit standard HTTP endpoints to add, delete, or alter data and to read a subset of entries that should be protected. This violation of confidentiality and integrity affects only a portion of the system’s data, as defined by the product’s access policies.
Affected Systems
Oracle Public Sector Financials versions 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are susceptible to this permission‑granting issue.
Risk and Exploitability
The vulnerability can be triggered over ordinary HTTP traffic by an attacker who has network access and low‑privilege credentials. The CVSS 3.1 base score of 5.4 indicates moderate risk, while an EPSS less than 1 % suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, but any compromised account can modify or read restricted data, potentially impacting the integrity and confidentiality of financial records.
OpenCVE Enrichment