Impact
A vulnerability in Oracle General Ledger allows a low‑privileged attacker with network access via HTTP to gain control of the application. Successful exploitation results in a full takeover of Oracle General Ledger, providing the attacker with complete read, modify, and delete capabilities and affecting confidentiality, integrity, and availability.
Affected Systems
Oracle General Ledger, part of Oracle E‑Business Suite, is affected in supported versions 12.2.3 through 12.2.15. Users of these releases should verify they are running one of the specified versions.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.8 indicates high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is network‑based via HTTP, with low access and privilege requirements, meaning an attacker does not need privileged credentials. Given the high CVSS score and the low barrier to exploitation, the risk is significant. Successful attacks can result in total application compromise.
OpenCVE Enrichment