Impact
This vulnerability in Oracle Production Scheduling allows a low‑privileged attacker with network access to HTTP to gain unauthorized access to the application. Successful exploitation can expose critical scheduling data or provide complete access to all data stored in the system, resulting in a confidentiality breach.
Affected Systems
The affected product is Oracle Production Scheduling, a component of Oracle E‑Business Suite’s Internal Operations. Supported versions from 12.2.3 through 12.2.15 are impacted by this issue.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 situates the vulnerability as moderate, with a significant confidentiality impact. The EPSS score of 0.00371 (roughly 0.4 %) indicates a very low probability of exploitation in the general population, yet the description notes it is easily exploitable and requires only network connectivity and low privilege. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits are currently documented.
OpenCVE Enrichment