Impact
A vulnerability in Oracle Bills of Material allows a low‑privileged network attacker with HTTP access to compromise confidentiality, integrity, and availability of the module, potentially enabling full takeover of the application. The flaw can impact additional Oracle E‑Business Suite components due to a scope change, allowing compromised credentials or execution paths to threaten adjoining systems.
Affected Systems
Oracle Bills of Material, a component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS Base Score of 8.5 indicates high severity. Exploitation requires only HTTP network access and an account with low privileges. The EPSS score is less than 1%, and the issue is not listed in CISA KEV. The likely attack vector is network traffic over HTTP to the Bills of Material endpoints, and the flaw’s scope may also affect other E‑Business Suite products.
OpenCVE Enrichment