Impact
The flaw resides in the Internal Operations component of Oracle Sales for Handhelds, part of the Oracle E‑Business Suite. A low‑privileged attacker who can reach the application’s HTTP interface can exploit the vulnerability, allowing the attacker to fully compromise the application. Successful exploitation results in complete loss of confidentiality, integrity, and availability for the Sales for Handhelds instance, effectively granting the attacker full administrative control and the ability to leverage the system for further attacks.
Affected Systems
Oracle Corporation’s Sales for Handhelds product, versions 12.2.3 through 12.2.15, is impacted. The vulnerability is confined to the Internal Operations component within the E‑Business Suite.
Risk and Exploitability
The vulnerability has a CVSS 3.1 Base Score of 8.8, indicating high severity with high impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, yet the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the publicly accessible HTTP interface, requiring only low privilege, which makes the vulnerability relatively easy to exploit for an attacker with network access to the affected system.
OpenCVE Enrichment