Impact
The vulnerability in Oracle Purchasing enables a low‑privileged attacker who can log onto the infrastructure that hosts the application to completely compromise the Oracle Purchasing environment. This flaw permits the attacker to achieve confidentiality, integrity, and availability impacts on the system. The CVSS 3.1 base score of 7.8 indicates high severity, with the attack vector defined as local, requiring low access, low complexity, and no user interaction.
Affected Systems
Affected versions include Oracle Purchasing 12.2.3 through 12.2.15. These versions are part of Oracle E‑Business Suite and rely on the Internal Operations component. Any deployment within this range without the patch is vulnerable.
Risk and Exploitability
The EPSS score of 0.00127 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, the CVSS base score of 7.8, combined with the local attack vector that requires a low‑privileged user, means the vulnerability remains high risk if local access is possible. An attacker who can log onto the server hosting Oracle Purchasing can leverage the flaw to gain full control and compromise the application.
OpenCVE Enrichment