Impact
The vulnerability affects Oracle Service Contracts in Oracle E‑Business Suite. An unauthenticated attacker with network access over HTTP can compromise the component, enabling the attacker to create, delete, or modify data and grant themselves or others unauthorized access to all accessible data. This leads to confidentiality and integrity impacts as described by the CVSS vector.
Affected Systems
Oracle Service Contracts product of Oracle E‑Business Suite, supported versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score of 7.4 indicates high severity, and the EPSS score of 0.00341 (less than 1%) indicates a very low exploitation probability, with the missing KEV listing further supporting the low likelihood of widespread exploitation. The attack requires straightforward network access via HTTP and no special privileges, but it leverages unauthenticated access to gain control over critical business data.
OpenCVE Enrichment