Impact
A flaw in the Service Request Form component of Oracle Teleservice permits an attacker with low privilege and network access via HTTP to compromise the application entirely. The vulnerability can lead to full takeover, resulting in loss of confidentiality, integrity, and availability of the affected system. The issue involves improper permission assignment (CWE‑284).
Affected Systems
Oracle Corporation's Oracle Teleservice, part of Oracle E‑Business Suite, is affected. The vulnerable versions include all releases from 12.2.3 through 12.2.15. The impact is on the Service Request Form functionality.
Risk and Exploitability
The flaw carries a high CVSS 3.1 base score of 8.8, indicating critical severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers require only low privileges with network access over HTTP, making the vulnerability readily exploitable and enabling full takeover of the service.
OpenCVE Enrichment