Impact
The vulnerability is an improper access control flaw in the Internal Operations component of Oracle Warehouse that allows a low‑privileged attacker who can reach the system over HTTP to create, delete or modify critical data, obtain full read access to all accessible data, and trigger an unrelated partial denial of service. This problem aligns with CWE‑284.
Affected Systems
The flaw affects Warehouse Management in Oracle E‑Business Suite, version 12.2.3 through 12.2.15, delivered by Oracle Corporation. Any installation of those releases that includes the Internal Operations component is impacted regardless of deployment configuration.
Risk and Exploitability
The CVSS v3.1 base score of 8.3 indicates high severity with confidentiality, integrity and availability impact. The vulnerability is easily exploitable via HTTP on the network with low privilege, and with an EPSS score of < 1%, the combination of network exposure and no need for elevated privileges makes this a priority. It is not yet listed in the CISA KEV catalog, suggesting no publicly known exploits at this time.
OpenCVE Enrichment