Impact
A flaw in Oracle Flow Manufacturing allows an attacker with limited privileges to bypass HTTP authentication, giving full control of the application. This vulnerability enables the attacker to compromise the system’s confidentiality, integrity, and availability by exploiting the authentication bypass in the Internal Operations component.
Affected Systems
Oracle Flow Manufacturing of Oracle E‑Business Suite, all supported versions from 12.2.7 to 12.2.15, is affected. The vulnerability lives in the Internal Operations module of the product.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS probability of less than 1 % suggests a low likelihood of widespread exploitation at present. The exploit requires network connectivity to the product’s HTTP interface and can be carried out with low‑privilege credentials; the primary attack vector therefore involves remote HTTP access to the affected system.
OpenCVE Enrichment