Impact
A vulnerability in Oracle Production Scheduling’s internal operations component allows an attacker with limited privileges and network access via HTTP to create, delete, or modify critical data, read restricted data, and trigger a partial denial of service. It correlates to information exposure, improper authorization, and resource exhaustion weaknesses.
Affected Systems
Oracle Production Scheduling from Oracle Corporation is affected, specifically versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 score is 7.6 with an indirect availability, integrity, and confidentiality impact. The EPSS score is less than 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The simplest attack path involves sending an HTTP request from a low‑privileged remote host to the exposed application, exploiting insufficient access controls.
OpenCVE Enrichment