Impact
The vulnerability resides in the Internal Operations component of Oracle Process Manufacturing Regulatory Management. It is an authority control flaw (CWE‑284) that allows a low‑privileged attacker who can reach the system over HTTP to create, delete or modify critical data. Successful exploitation can result in unauthorized access to all data exposed by the product, effectively compromising confidentiality and integrity of the manufacturing regulatory information.
Affected Systems
Oracle Process Manufacturing Regulatory Management, part of the Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score is 8.1, indicating a high severity with significant confidentiality and integrity impacts. The EPSS score of less than 1% suggests a low probability of exploitation so far, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network access over HTTP and a low‑privileged user account; no privileged credentials or code execution are necessary. Because the flaw involves missing proper authorization checks, an attacker can easily perform the malicious actions described if they can reach the Internal Operations component.
OpenCVE Enrichment