Impact
A vulnerability exists in the Import And Export component of Oracle Learning Management, allowing a user with low privileges and network access via HTTP to gain unauthorized capabilities. The flaw enables attackers to update, insert, or delete data, read restricted data, and trigger a partial denial of service, impacting confidentiality, integrity, and availability. The weakness is a combination of improper access control (CWE‑284), information exposure (CWE‑200), and SQL injection (CWE‑89).
Affected Systems
Oracle Learning Management versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS score is 6.3, indicating a moderate severity. The EPSS score is less than 1 percent, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. Nonetheless, exploitation would enable a low‑privileged attacker to modify or read data and cause service disruption. The likely attack vector is remote access over HTTP from a non‑privileged user, making it easily exploitable by anyone who can reach the service on the network.
OpenCVE Enrichment