Impact
A flaw in Oracle iSupplier Portal enables attackers who can reach the service via HTTP to create, delete, or modify critical data without authentication. The vulnerability results in confidentiality and integrity breaches for all data that the portal exposes. The attack requires no privileged credentials, lowering the barrier to exploitation.
Affected Systems
Vulnerable versions are Oracle iSupplier Portal 12.2.3 through 12.2.15, part of the Oracle E‑Business Suite Internal Operations component. The vulnerability affects installations that expose the portal’s HTTP interface to a network, whether internally or externally.
Risk and Exploitability
The CVSS base score of 7.4 reflects high confidentiality and integrity impact, and the attack vector is network based but requires unauthenticated access over HTTP. Based on the description, it is inferred that the exploit requires moderate technical skill and network reachability. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation but still posing a significant risk in exposed environments.
OpenCVE Enrichment