Impact
Vulnerability in the Internal Operations component of Oracle Yard Management allows an attacker with network access via HTTP and low privileges to compromise the system. Successful exploitation can result in a full takeover, granting the attacker control over confidential, integrity, and availability aspects of the application. This exposure is documented with a CVSS 3.1 base score of 8.8, highlighting high impact.
Affected Systems
Affected product is Oracle Yard Management within Oracle E‑Business Suite. Oracle acknowledges versions 12.2.3 through 12.2.15 as impacted. The vulnerability is specific to the Yard Management module when accessed over HTTP.
Risk and Exploitability
The CVSS score of 8.8 places the flaw in the high severity range, and although EPSS data is not available, the description labels it as easily exploitable. The attack vector is network-based via HTTP, requiring only low-level privileges and no user interaction, which increases the likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment