Impact
Oracle Sales Foundation’s Security API contains a flaw that permits a low‑privileged network attacker to create, delete, or modify records and gain read access to all data exposed by the application. This results in a high confidentiality impact because sensitive data can be disclosed or destroyed, and a high integrity impact because data can be altered without authorization. The weakness is an improper access control that allows privileged operations without proper authorization checks. The vulnerability is easily exploitable through standard HTTP connections, requiring no special credentials beyond those of a user with minimal privileges.
Affected Systems
The affected product is Oracle Sales Foundation, part of Oracle E‑Business Suite, specifically the Security API component. Oracle lists supported versions 12.2.3 through 12.2.15 as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 categorizes this as a high‑severity vulnerability, and the report notes that it is easily exploitable by an attacker with network access to the HTTP interface. EPSS score is 0.00365, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is inferred from the description (network HTTP), it is considered external with low effort and low privileges required.
OpenCVE Enrichment