Impact
The flaw is an improper authorization vulnerability in the Oracle Sales Foundation Security API, exemplifying CWE-284 (Improper Access Control). A low‑privileged attacker who can reach the exposed HTTP endpoint can exploit this access control weakness to gain unauthorized control of the Sales Foundation instance, potentially leading to full takeover and compromising confidentiality, integrity, and availability of all data accessed through it.
Affected Systems
Oracle Corporation’s Oracle Sales Foundation product, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 classifies this as high severity. An EPSS score of less than 1% indicates a low but nonzero probability of real‑world exploitation. This vulnerability is not listed in the CISA KEV catalog. The affected URL is reachable over HTTP from external networks, giving an attacker a network‑level entry vector to the Security API without authenticating originally or with only limited credentials. The weakness stems from lack of proper authorization checks.
OpenCVE Enrichment