Impact
The vulnerability resides in the Fulfillment Engine component of Oracle Service Fulfillment Manager, permitting an attacker with low privileges and network access via HTTP to compromise the system. The CVSS vector indicates a high confidentiality impact and a low integrity impact, and the weakness exposes critical data that could be read, updated, inserted, or deleted.
Affected Systems
Impact is limited to Oracle Corporation's Service Fulfillment Manager included in Oracle E‑Business Suite. Affected versions range from 12.2.3 through 12.2.15. While the vulnerability is tied to this product, the description notes that attacks may also affect other products within the Oracle suite due to the scope change.
Risk and Exploitability
The CVSS score of 7.6 classifies the flaw as high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote over the network, requiring HTTP access and a low‑privilege credential, with the vector implying the vulnerability can successfully be exploited with user interaction from a different person. Given the scope change, a compromise can lead to privilege escalation within the Service Fulfillment Manager environment.
OpenCVE Enrichment