Impact
The vulnerability in Oracle Cash Management permits a high-privilege local user to perform unauthorized creation, deletion, or modification of critical data, as well as gain unauthorized access to any data the application can access. This flaw directly compromises confidentiality and integrity of all managed treasury data, potentially allowing full data exposure or manipulation.
Affected Systems
Oracle Corporation's Oracle Cash Management component of Oracle E-Business Suite, versions 12.2.3 through 12.2.15 - specifically the Internal Operations portion - is affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.0 indicates moderate severity, with a local attack vector, low complexity, high privilege requirement, no user interaction, and combined confidentiality and integrity impact. Because the vulnerability requires access to the host where the application runs, it is not remotely exploitable; however, an attacker who has already elevated privileges locally or compromised an administrator account could trigger the flaw immediately. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation, but the high-privilege nature and data-critical impact warrant priority patching.
OpenCVE Enrichment