Impact
A vulnerability in Oracle General Ledger’s internal operations component enables a low‑privileged user with network access via HTTP to gain unauthorized read, write, or delete access to critical general ledger data and to trigger a partial denial of service. The weakness stems from improper access controls and lack of proper authorization enforcement, allowing the attacker to compromise the confidentiality, integrity and availability of the ledger.
Affected Systems
Vulnerable versions of Oracle General Ledger in Oracle E‑Business Suite, from 12.2.3 through 12.2.15, are affected. The issue resides in the internal operations component and can be exploited over the network through HTTP interfaces.
Risk and Exploitability
The CVSS 3.1 base score of 7.6 indicates a high severity. No EPSS data is available, so the current exploitation likelihood is unknown, but the vulnerability is public and easily exploitable from any networked environment that can reach the HTTP endpoints. Because the attack relies on low privilege credentials, an attacker who can obtain such credentials is capable of compromising all accessible ledger data. The vulnerability is not listed in CISA’s KEV catalog, yet its high impact warrants immediate attention.
OpenCVE Enrichment