Impact
A vulnerability in Oracle Partner Management enables an unauthenticated attacker with HTTP network access to retrieve or modify data. The weakness allows the attacker to read confidential data, insert or delete records, and gain full control over data accessible in the application. The impact spans confidentiality and, in certain configurations, integrity, as documented by a CVSS 3.1 score of 8.2, with a scope change effect.
Affected Systems
Oracle Corporation’s Oracle Partner Management component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is impacted. The product is identified as a partner management module and is exposed via web interfaces that accept HTTP traffic.
Risk and Exploitability
The vulnerability is exploitable by users with no authentication and requires an attacker to have network access to the target HTTP endpoint. While successful exploitation needs a second human interaction, the weakness can still lead to significant data compromise. The CVSS score reflects moderate to high severity, and the EPSS score is not available, but the lack of a KEV listing suggests exploitation is not yet widely documented. The scope change indicates that compromise of this module may affect other integrated products and services.
OpenCVE Enrichment