Impact
A remote SQL injection flaw exists in Oracle Demantra Demand Management that allows an attacker with low privileges and network access to send specially crafted SQL commands. Successful exploitation results in full compromise of the application, giving the attacker complete control and allowing malicious modification or extraction of confidential data, as well as interruption of service. This vulnerability is classified as a high‑severity flaw because it affects confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Demantra Demand Management product, versions 12.2.3 through 12.2.15, is affected. The flaw resides in the Product Security component of the Supply Chain suite.
Risk and Exploitability
The CVSS 3.1 score of 8.8 indicates a critical impact on all core security aspects. The EPSS score is less than 1%, suggesting that exploitation in the wild is currently unlikely but possible. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based SQL query over the open interface, and success requires only low‑privilege user permissions.
OpenCVE Enrichment