Impact
In Oracle Payables, a flaw allows an attacker who has low privileges and can reach the system over HTTP to create, delete, or alter critical financial records. This results in confidentiality and integrity violations, as sensitive data can be accessed or tampered with without authorization. The weakness originates from insufficient access control checks on privileged operations within the Internal Operations component.
Affected Systems
Oracle Payables versions 12.2.3 through 12.2.15 from Oracle Corporation are impacted.
Risk and Exploitability
The CVSS 3.1 score of 8.1 reflects a moderately high risk, with Network access, low attack complexity, and low privilege required; no user interaction is needed. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, the easy network accessibility and potential for significant data compromise warrant immediate attention.
OpenCVE Enrichment