Impact
A low privileged attacker with network access via HTTP can exploit the Oracle Succession planning component and perform unauthorized updates, inserts, or deletes, read restricted data, and trigger a partial denial of service. The weakness stems from improper input validation and inadequate access controls, corresponding to the listed CWEs. The exploit can affect multiple facets of the application, compromising confidentiality, integrity, and availability of the system’s data.
Affected Systems
Oracle Succession planning product in Oracle E-Business Suite, versions 12.2.3 through 12.2.15, is impacted.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 6.3, indicating moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is likely via direct HTTP requests from a low privileged network user, perhaps internal, who can send malformed or unauthorized requests to the Succession plan interfaces.
OpenCVE Enrichment