Impact
The vulnerability in Oracle Risk Management allows a low-privileged attacker with HTTP network access to fully compromise the application. The flaw can be exploited easily and results in loss of confidentiality, integrity and availability, essentially enabling full system takeover. This weakness aligns with improper access control, permitting unauthorized manipulation of the Risk Management system.
Affected Systems
Oracle Risk Management, part of Oracle E-Business Suite, is affected in all supported releases from version 12.2.3 through 12.2.15. Systems running these product versions that expose the Internal Operations component to network traffic are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score is 8.8, indicating high severity. The EPSS score is less than 1%, reflecting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP and requires only low-privileged access; once an attacker reaches the application, they can achieve complete takeover.
OpenCVE Enrichment