Impact
The flaw in Oracle Customer Care's Internal Operations component can be abused by a low‑privileged attacker who has network access to the web interface. With only user interaction from a third party, an attacker may create, delete or modify critical data and gain read access to all Oracle Customer Care data. The weakness involves improper access control and authorization bypass. The vulnerability is evaluated as CVSS 3.1 with a base score of 8.7, indicating high impact on confidentiality and integrity, while availability remains unaffected.
Affected Systems
The affected product is Oracle Customer Care, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are specifically vulnerable to this issue. No other products or versions are listed in the available data.
Risk and Exploitability
The CVSS score of 8.7 and the semi‑interactive nature of the exploitation (requiring human interaction) result in a high risk level. Because the vulnerability can affect scope and alter the integrity of all data exposed by Oracle Customer Care, the threat is significant for environments that host this application. The EPSS score indicates a low probability of exploitation (approximately 0.3%), and the issue is not listed in the CISA KEV catalog, but the combination of a high CVSS, network‑based attack vector and potential cross‑product impact warrants prompt attention.
OpenCVE Enrichment