Impact
The vulnerability exists in the internal operations component of Oracle Transportation Execution, a module of Oracle E‑Business Suite. A low‑privileged attacker who can reach the system over HTTP can exploit the flaw if they obtain the cooperation of a user who is not the attacker. Exploitation would give the attacker the ability to create, delete or modify critical data, and to read a subset of data that the victim user has access to. This is an improper authorization failure that undermines confidentiality and integrity for the affected data.
Affected Systems
The flaw affects Oracle Corporation’s Oracle Transportation Execution products, versions 12.2.3 through 12.2.15, which are part of Oracle E‑Business Suite. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.6 indicates high severity with moderate confidentiality impact and high integrity impact. The vector shows network access, low complexity, low attacker privilege, required user interaction, and a scope change, meaning that once the attacker has achieved access they may impact additional components. The EPSS score is 0.00262, indicating an extremely low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the requirement for user interaction reduces the likelihood of automated attacks, and the need for low‑privilege access limits the barrier to exploitation. In a corporate environment, the combination of network exposure over HTTP and the ability to compromise data integrity makes the risk non‑negligible.
OpenCVE Enrichment