Impact
The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite. An attacker who can reach the application via HTTP and only requires a low-privileged account may trigger missing authorization checks to read all Order Management data and perform unauthorized insert, update or delete operations. The flaw results in high confidentiality loss and lower but still significant integrity impact, allowing an attacker to modify or delete records they normally could not access.
Affected Systems
Affected are Oracle Order Management installations running versions 12.2.3 through 12.2.15, part of Oracle E-Business Suite. The product is exposed to normal HTTP traffic, and the vulnerability can be exploited by any user with network connectivity to that service. Although the flaw is confined to Order Management, the scope change noted in the CVSS vector means that compromising this component could also affect other integrated Oracle products.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 classifies the issue as high severity. EPSS of 0.00242 indicates a very low yet non-zero probability of exploitation in the near term. The vulnerability is not listed in CISA KEV. Attackers can act externally over the network (AV:N), with high complexity but only low privilege (PR:L) and no user interaction required. The likely attack vector is a HTTP request to a diagnostic endpoint, making the flaw remote in nature and potentially exploitable by relatively unsophisticated threat actors.
OpenCVE Enrichment