Impact
Vulnerability in Oracle Production Scheduling allows unauthenticated attackers with network access over HTTP to potentially compromise the system. The attack requires human interaction from a user other than the attacker and would result in unauthorized access to critical data or complete control over all data accessible by the Scheduling application. The flaw is rated moderate with a CVSS base score of 5.3, indicating effect.
Affected Systems
Affected instances include Oracle Corporation's Oracle Production Scheduling component of the Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. This product uses the Internal Operations module, and only the stated versions are known to be vulnerable.
Risk and Exploitability
The risk of exploitation is considered moderate. The CVSS score reflects moderate severity, while the EPSS score of less than 1% suggests a low probability of real-world exploitation. With the vulnerability not listed in the CISA KEV database, it has no known widespread exploitation. Attackers would need HTTP access to the exposed service and a victim to interact with the application; the lack of authentication lowers the barrier, but the requirement of human interaction limits immediate exploitation potential.
OpenCVE Enrichment