Impact
Oracle SDP Number Portability suffers a local privileged vulnerability that permits an attacker with administrative access to create, delete, or alter critical data, as well as to read restricted fields. The flaw enables unauthorized modification of the data store and can trigger a partial denial of service, affecting the confidentiality, integrity, and availability of Oracle SDP Number Portability. The weakness can be classified as improper access control (CWE-284).
Affected Systems
The product Oracle SDP Number Portability, part of Oracle E-Business Suite, is affected in all supported releases from 12.2.3 up to and including 12.2.15. Affected instances run on infrastructure where the Oracle SDP Number Portability component is executed.
Risk and Exploitability
The CVSS 3.1 base score is 7.3, which reflects high severity. Exploitation requires Local access with high privileges; the attacker must already have administrative login on the host. The vulnerability can change the scope to impact additional Oracle products, meaning that a compromise may cascade beyond the SDP Number Portability component. The EPSS score is 0.00139 and the vulnerability is not listed in the CISA KEV catalog, the high privilege prerequisite and potential for data tampering make it a critical internal threat. Attackers would typically exploit the flaw by logging into the infrastructure, then issuing privileged commands that modify the SDP data or disable service function to cause partial denial of service.
OpenCVE Enrichment