Impact
The vulnerability allows an attacker with high privileges and network access via HTTP to compromise Oracle Cost Management, resulting in a full takeover of the application. It is an easily exploitable remote vulnerability that can affect Confidentiality, Integrity, and Availability, reflected in a CVSS 3.1 Base Score of 7.2.
Affected Systems
Affected systems are Oracle Corporation’s Oracle Cost Management product within Oracle E‑Business Suite, specifically the Cost Planning component. Versions from 12.2.3 through 12.2.15 are impacted, while later releases are not listed as affected.
Risk and Exploitability
The risk is high because the attack vector is network‑based over HTTP and exploitation would grant the attacker complete control of the application. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score indicates a high likelihood of severe impact if exploited.
OpenCVE Enrichment