Impact
A flaw in Oracle Process Manufacturing Regulatory Management’s internal operations component allows an attacker with low privileges and network access over HTTP to read, insert or delete data that the application normally protects, enabling unauthorized access to critical information and potential data alteration. The listed CVSS vector shows high confidentiality impact, low integrity impact, and no availability impact, meaning the main danger is to data privacy and accuracy rather than service disruption.
Affected Systems
The vulnerability affects Oracle Process Manufacturing Regulatory Management versions 12.2.3 through 12.2.15. It is noted that the flaw is tied to the internal operations code and a scope change indicates that other Oracle E‑Business Suite products that share this code might also be impacted.
Risk and Exploitability
With a CVSS base score of 8.5 the issue is high severity. The EPSS score of less than 1% suggests that while exploitation has not been widely observed, the vulnerability remains exploitable if an attacker can reach the HTTP interface. The flaw is not yet listed in CISA’s KEV catalog, but the combination of remote, low‑privilege access, and significant confidentiality impact makes prompt remediation prudent.
OpenCVE Enrichment