Impact
An easily exploitable flaw in Oracle Purchasing’s Internal Operations component permits a high‑privileged attacker who can reach the web interface to compromise the application. The vulnerability gives full control, resulting in a complete takeover of Oracle Purchasing and exposing the confidentiality, integrity, and availability of all assets managed by the product. The CVSS 3.1 vector indicates that no user interaction is required and that the impact is high across all three CIA dimensions.
Affected Systems
Oracle Purchasing versions 12.2.3 through 12.2.15 are affected. The issue is specific to the Internal Operations component of Oracle E‑Business Suite.
Risk and Exploitability
The flaw has a CVSS Base Score of 7.2, reflecting moderate-to-high risk. Attackers can exploit it by sending crafted HTTP requests, without requiring authentication beyond a privileged session. The EPSS score of 0.00342 (<1%) indicates a very low exploitation probability, and the absence of a KEV listing further suggests that this vulnerability is not currently widely exploited, but still represents a significant risk to organizations running the affected releases.
OpenCVE Enrichment