Impact
Oracle Installed Base contains a flaw in its User Interface component that allows a low‑privileged attacker with HTTP network access to modify, insert, delete, or read restricted data and to trigger a partial denial of service. The weakness is insufficient authorization and missing privilege separation, classifying as CWE‑284. The impact is unauthorized data manipulation and partial service interruption.
Affected Systems
The issue affects Oracle Installed Base in Oracle E‑Business Suite versions 12.2.3 through 12.2.15, inclusive. All deployments of the User Interface component that support these versions are potentially vulnerable. The product impacted is Oracle Installed Base from Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 places the vulnerability in a medium severity range. The EPSS score is under 1 %, indicating a low probability of active exploitation, and it is not listed in the CISA KEV catalog. Attack characteristics include a network‑based HTTP vector, low attack complexity, low privilege requirement, and no user interaction. The flaw does not allow arbitrary code execution; it permits unauthorized data operations and partial service disruption.
OpenCVE Enrichment