Impact
The vulnerability is an easily exploitable weakness in Oracle Yard Management that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation results in full takeover, thereby compromising confidentiality, integrity, and availability of the Yard Management system. The weakness falls under improper access control or privilege escalation concerns, as the attacker can bypass intended permissions.
Affected Systems
Oracle Corporation’s Oracle Yard Management component of Oracle E-Business Suite is impacted. The affected releases are all versions from 12.2.6 through 12.2.15, inclusive.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 signals high severity, and the same vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows that a remote, low-privileged user can reach the flaw. EPSS is under 1%, indicating that hacking attempts are historically uncommon, and the flaw is not yet listed in the CISA KEV catalogue. Based on the description, it is inferred that a likely attack scenario involves an attacker discovering an exposed HTTP endpoint, sending a crafted request that exploits the underlying access control flaw, and executing arbitrary code or commands, thereby taking over the Yard Management instance.
OpenCVE Enrichment