Impact
The vulnerability lies in the Oracle Sales component of Oracle E‑Business Suite, allowing an attacker with low privileges who can access the system over HTTP to create, delete, or modify critical data. This results in loss of confidentiality and integrity for all data stored or accessed through Oracle Sales. The weakness stems from inadequate access control mechanisms that bypass proper authorization checks.
Affected Systems
Oracle Corporation’s Oracle Sales product, part of the Oracle E‑Business Suite, is affected. The related Internal Operations component runs versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 score of 8.1 reflects a high severity with significant confidentiality and integrity impact. An EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based using HTTP, requiring only low‑privileged access. Any user who can reach the exposed Oracle Sales instance can potentially exploit this flaw, making it a serious threat for systems exposed to untrusted networks.
OpenCVE Enrichment