Impact
The vulnerability is an improper access control flaw in the Internal Operations component of Oracle Flow Manufacturing, classified as CWE‑284. It allows attackers with low‑privileged accounts and network access via HTTP to create, delete, or modify critical data and to read all data that they can reach through the web interface. This breach directly compromises both confidentiality and integrity of the application data.
Affected Systems
Affected are Oracle Corporation’s Oracle Flow Manufacturing product, versions 12.2.13 through 12.2.15 inclusive, which are part of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 signals a high-impact vulnerability, while the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in CISA KEV, so no publicly documented exploits are known. Because an attacker only needs a low‑privilege user account and network connectivity via HTTP, the risk to exposed systems remains significant, especially if role‑based access controls are not properly enforced.
OpenCVE Enrichment