Impact
The vulnerability in the Oracle Customers Online component of Oracle E‑Business Suite allows a remote attacker with low privilege who can reach the system over HTTP to compromise the application. An exploit can lead to full takeover of Oracle Customers Online, resulting in loss of confidentiality, integrity, and availability. The weakness is rated with a CVSS 3.1 base score of 8.8, indicating a high‑impact attack.
Affected Systems
Affected are Oracle Customers Online within Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. The weakness resides in the Customer Tab component.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. No EPSS score is supplied, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is network‑based over HTTP, requiring only low privilege. Successful exploitation would give the attacker control over the application, enabling data exfiltration, modification, or denial of service.
OpenCVE Enrichment