Impact
A vulnerability in Oracle Flow Manufacturing’s internal operations component permits an attacker with low privilege and network access via HTTP to read critical operational data and, in some cases, modify, insert, or delete that data. The flaw enables unauthorized disclosure of confidential information and compromises data integrity, as described by the CVSS 3.1 Base Score of 7.1, which marks high confidentiality impact and low integrity impact.
Affected Systems
Oracle Flow Manufacturing, part of Oracle E‑Business Suite, is affected from version 12.2.3 through 12.2.15. The vulnerability targets the internal operations component of the product.
Risk and Exploitability
The CVSS score denotes moderate to high severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The flaw is exploitable over the network through HTTP without requiring elevated privileges or local access. Although the vulnerability is not listed in the CISA KEV catalog, its combination of network exposure and low privilege makes it a candidate for compromise, especially in environments that have not applied the latest security updates or instituted restrictive network controls.
OpenCVE Enrichment