Impact
The vulnerability exists in the Internal Operations component of Oracle Sales, part of Oracle E‑Business Suite. It allows a low‑privileged user with network access to the HTTP interface to compromise the application. The weakness is an access control flaw (CWE‑284) that enables the attacker to bypass normal controls. Successful attacks can result in takeover of Oracle Sales, giving the attacker full control over the application, including potential to read, modify, or delete data and disrupt services.
Affected Systems
Oracle Corporation’s Oracle Sales product in Oracle E‑Business Suite, supported versions 12.2.3 through 12.2.15, is impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates high severity, and the vector shows remote network exploitation with low privileged interaction. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, but the risk remains because an attacker can exploit the flaw over HTTP and acquire full control of Oracle Sales. The likely attack vector is attempting unauthenticated or minimally privileged access to the HTTP endpoints of the Internal Operations component, which, if successful, would result in takeover of Oracle Sales.
OpenCVE Enrichment