Impact
A vulnerability exists in the Party Search UI component of Oracle Trading Community that allows an unauthenticated attacker who can reach the application over HTTP to compromise the entire application, potentially leading to a full takeover that affects confidentiality, integrity, and availability. The CVSS 3.1 Base Score of 8.1 and vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H reflect the high severity of this flaw.
Affected Systems
Oracle Trading Community, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS Base Score of 8.1 indicates a high impact, and the EPSS score of less than 1 percent means exploit probability is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the exploitation difficulty is high because the flaw is described as "difficult to exploit", and the attack can be performed over un‑authenticated HTTP traffic. These factors combine to make the risk high but the likelihood of successful exploitation low.
OpenCVE Enrichment