Impact
An attacker with low privileges and network access over HTTP can exploit a flaw in Oracle Purchasing’s Internal Operations component to create, delete, or modify critical data. The vulnerability permits unauthorized access to all data accessible within Oracle Purchasing, compromising confidentiality and integrity of the system’s information.
Affected Systems
Oracle Purchasing components of Oracle E-Business Suite, versions 12.2.3 through 12.2.15, are affected. The flaw resides in the Internal Operations component and is exploitable across all installations of these versions without additional conditions.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates a high severity level. The attack requires only network access over HTTP and local or low privileges, making it relatively easy to execute. The EPSS score of < 1% indicates a very low probability of exploitation, but the vulnerability remains significant due to its high CVSS, and it is not listed in CISA's KEV catalog.
OpenCVE Enrichment