Impact
A flaw in the Internal Operations component of Oracle Risk Management allows an attacker with low‑privileged network access via HTTP to create, delete, or modify critical data. The vulnerability results in high confidentiality and integrity impacts as described by the CVSS 3.1 score of 8.1. It reflects weaknesses in both least privilege and improper authorization, tied to CWE‑284.
Affected Systems
The Oracle Risk Management product of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. These versions are offered by Oracle Corporation.
Risk and Exploitability
The likely attack vector is a remote HTTP request from a network host that an attacker can reach. The EPSS score is <1% and the vulnerability is not listed in CISA's KEV catalog, but the CVSS score indicates substantial impact on confidentiality and integrity. Because the flaw is remotely exploitable via HTTP with only low privileges required, the risk to exposed systems is moderate to high.
OpenCVE Enrichment