Impact
The vulnerability is an improper access control flaw (CWE-284) in Oracle Advanced Benefits’ Self Service Benefits component. It allows a low‑privileged user who can reach the application via HTTP to update, insert, or delete benefit records, read sensitive benefit information that should not be exposed, or cause a partial denial of service. These actions can compromise the confidentiality, integrity, and availability of the data managed by the application.
Affected Systems
Oracle Advanced Benefits, part of Oracle E‑Business Suite, is affected in the Self Service Benefits module. Versions 12.2.3 through 12.2.15 contain the weakness. Organizations using any of these releases should verify and isolate the component.
Risk and Exploitability
The CVSS 3.1 Base Score of 6.3 indicates a moderate severity. The EPSS score of less than 1 % indicates very low current exploitation activity, and the vulnerability is not listed in CISA’s KEV catalog. However, the flaw can be exploited from any host that can reach the service over HTTP with a low‑privileged account, making the attack path simple. The potential to modify or delete benefit records or read protected data means that a successful exploit could lead to significant data loss or corruption, and the possible denial of service could disrupt business operations.
OpenCVE Enrichment