Impact
An attacker with low privileges and network access over HTTP can leverage a flaw in Oracle Purchasing to create, delete, or modify critical data. The vulnerability permits unauthorized privileged access to all data accessible within Oracle Purchasing, severely compromising confidentiality and integrity of the system’s information. The impact includes loss of data integrity, potential data exfiltration, and unauthorized data manipulation that can disrupt business operations.
Affected Systems
Oracle Purchasing components of Oracle E-Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw resides in the Internal Operations component and is exploitable across all installations of these versions without additional conditions.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates a high severity level. The attack requires only network access over HTTP and local or low privileges, making it relatively easy to execute. The EPSS score was not available, and the vulnerability is not listed in CISA's KEV catalog, but the lack of current exploitation data does not lower the assessed risk due to the high CVSS score and the ease of exploitation in a typical network environment.
OpenCVE Enrichment