Impact
A flaw in Oracle Advanced Planning Command Center allows an attacker who already has high‑privilege access and can reach the application via HTTP to compromise the component, enabling unauthorized reading of all accessible data and the ability to insert, update or delete critical information. The vulnerability carries confidentiality and integrity impacts and is identified with a CVSS 7.6 score, indicating high severity. The effect is amplified by a potential scope change that could impact additional Oracle products.
Affected Systems
Oracle Advanced Planning Command Center versions from 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are affected. No other product or version is listed as impacted.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation today. The vulnerability is not in CISA’s KEV catalog. The risk is heightened by the possible scope change. Exploitation requires HTTP network access and an account with high privileges; no additional sophisticated conditions are mentioned.
OpenCVE Enrichment