Impact
The flaw in Oracle Proposals lets an attacker with network access through HTTP compromise the application, potentially leading to a full takeover of Oracle E‑Business Suite. The CVSS vector indicates that the attacker must possess high privileges (PR:H) but no user interaction is required. The impact is broad—confidentiality, integrity and availability are all at risk, effectively giving the attacker loss of control over the affected system.
Affected Systems
Oracle Proposals versions 12.2.3 through 12.2.15 in the Internal Operations component are affected. Only Oracle Corporation’s Oracle Proposals product is impacted; no other vendors or products are listed.
Risk and Exploitability
The CVSS base score of 7.2 marks this a high‑severity issue, and the EPSS score of < 1% indicates a very low exploitation probability, while the lack of a KEV listing suggests it has not yet been widely exploited in the wild. The vulnerability is remotely exploitable over HTTP, meaning an attacker who can reach the service can potentially compromise the entire application without additional privileges beyond those already held. Because the flaw grants high‑level control, the risk to organizations using the affected releases is significant and should be addressed promptly.
OpenCVE Enrichment