Impact
A vulnerability in Oracle Purchasing allows a low-privileged attacker with network access through HTTP to achieve a complete compromise of the application, affecting confidentiality, integrity, and availability. The flaw is difficult to exploit but succeeds in taking over the system when triggered, resulting in full control over Oracle Purchasing. The weakness is characterized by CWE-269, CWE-284, CWE-287, and CWE-306.
Affected Systems
Oracle Purchasing in Oracle E‑Business Suite, with affected releases 12.2.11 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score is 7.5, indicating a high severity level. The EPSS score of <1% shows a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to be a low‑privileged user with network access to the HTTP endpoint; once leveraged, the attacker can take full control of the application.
OpenCVE Enrichment