Impact
A low‑privileged attacker with network access via HTTP can exploit a flaw in Oracle Sales, part of Oracle E‑Business Suite, to bypass normal access controls and read or modify critical data. The vulnerability exposes both confidentiality — by allowing the attacker to view sensitive sales information — and integrity — by enabling unauthorized insert, update, or delete operations on the database. The underlying weakness is an access‑control failure (CWE-284).
Affected Systems
Oracle Sales, Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. These versions include the Internal Operations component and are reachable over HTTP. No other Oracle product versions are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 reflects a medium‑to‑high severity impact with high confidentiality loss and low integrity loss. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the HTTP endpoint; the exploit requires low privileged user credentials on the target network. Successful exploitation grants the attacker full access to all Sales‑accessible data and the ability to modify or delete records.
OpenCVE Enrichment