Impact
A flaw in the Oracle Customer Care application allows a high‑privileged attacker with network access via HTTP to compromise the system. The vulnerability permits unauthorized creation, deletion, or modification of critical data, as well as full access to all customer‑care data. The impact is a loss of confidentiality and integrity for the affected database contents.
Affected Systems
Oracle Corporation’s Oracle E‑Business Suite, specifically the Customer Care component of Internal Operations, is affected in versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 indicates high severity. The lack of an EPSS score suggests limited public exploitation data, but the vulnerability is described as easily exploitable and the attack vector is network access over HTTP. The vulnerability’s scope allows a high‑privileged user to affect other products as well, increasing the overall risk. The issue is not listed in CISA’s KEV catalog, meaning no known public exploit has been reported yet.
OpenCVE Enrichment